Přejít na obsah
Menu
You need to be registered to interact with the community.
This question has been flagged
1 Odpovědět
298 Zobrazení

To secure production enviornment from Brute force attack Odoo has implemented login_cooldown_after

It working fine when workers = 0

The moment i activate/ put worker >0 it does not work and did not produce failour count

as it not sharing login attempt counter between different process.


what is the alternative solution and is not possible to use login_cooldown_after in multithreading environment?

Avatar
Zrušit
Nejlepší odpověď

odoo stores logins trials in registry so you can not guarantee which worker(process) the user will try each time. the best solution suggested from odoo use tool like fail2ban

source https://www.odoo.com/documentation/18.0/administration/on_premise/deploy.html#blocking-brute-force-attacks

Avatar
Zrušit
Autor

it means login_cooldown_after feature is useless!!