[PR #11699] make login lockout duration configurable #27327

Closed
opened 2026-02-21 20:41:18 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/11699

State: closed
Merged: Yes


Summary

This is the implementation for #11698

When login attempts exceeds limit, login lockout happens for security reason, which is reasonable. However, currently lockout duration is too long i.e. 24hours, and it's not configurable.
I believe this is inconvinient depending on the environments being used and so making it configurable via .env file in api.

Changes are:

  • api/configs/feature/__init__.py: adding LOGIN_LOCKOUT_DURATION to AuthConfig class with default=86400(24hours).
  • .env.example: adding template parameter in .env.example having value equal to default value
  • api/services/account_service.py: changing timeout seconds of redis_client.setex function used to calculate login error count in add_login_error_rate_limit function

Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change.

Tip

Close issue syntax: Fixes #<issue number> or Resolves #<issue number>, see documentation for more details.

Screenshots

Before After
... ...

Checklist

Important

Please review the checklist below before submitting your pull request.

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/11699 **State:** closed **Merged:** Yes --- # Summary **This is the implementation for #11698** When login attempts exceeds limit, login lockout happens for security reason, which is reasonable. However, currently lockout duration is too long i.e. 24hours, and it's not configurable. I believe this is inconvinient depending on the environments being used and so making it configurable via .env file in api. Changes are: - **api/configs/feature/__init__.py:** adding LOGIN_LOCKOUT_DURATION to AuthConfig class with default=86400(24hours). - **.env.example:** adding template parameter in .env.example having value equal to default value - **api/services/account_service.py:** changing timeout seconds of redis_client.setex function used to calculate login error count in add_login_error_rate_limit function Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. > [!Tip] > Close issue syntax: `Fixes #<issue number>` or `Resolves #<issue number>`, see [documentation](https://docs.github.com/en/issues/tracking-your-work-with-issues/linking-a-pull-request-to-an-issue#linking-a-pull-request-to-an-issue-using-a-keyword) for more details. # Screenshots | Before | After | |--------|-------| | ... | ... | # Checklist > [!IMPORTANT] > Please review the checklist below before submitting your pull request. - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [ ] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [ ] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:41:18 -05:00
yindo closed this issue 2026-02-21 20:41:18 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#27327