Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unexpected behavior while using WebDAV with email address in login credentials #211

Open
wollomatic opened this issue Aug 2, 2023 · 0 comments

Comments

@wollomatic
Copy link

Brute Force Protection Version 1.2.0
Owncloud 10.12.0 (stable)

When using WebDAV and the Brute Force Protection App is Enabled, there is a different behaviour when I use an email address and password than when I use a username and password:

Using WebDAV with username + password:
Everything works as expected.

Using WebDAV with email address + password:
First, everything works as expected.
But then, after n requests, the brute force protection gets active, and I get a 401 status code.

Is Brute Force Protection identifying the correct WebDAV requests as a brute force attack when I use an email address instead of the username?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant