|
|
7cc5cad14f
|
security: enhance authentication rate limiting and add comprehensive security tests
- Add rate limiting middleware for NextAuth login endpoints
- Implement authRateLimitMiddleware for /api/auth/* routes
- Add comprehensive security tests covering:
- Rate limiter functionality (5 tests)
- IP extraction from headers (5 tests)
- Input validation and sanitization (10 tests)
- Password strength requirements
- XSS and SQL injection prevention
- All 21 security tests passing
- Rate limits configured: 5 login attempts per 15 minutes
|
2025-07-12 00:27:51 +02:00 |
|