Passa al contenuto
Menu
È necessario essere registrati per interagire con la community.
La domanda è stata contrassegnata
1 Rispondi
305 Visualizzazioni

To secure production enviornment from Brute force attack Odoo has implemented login_cooldown_after

It working fine when workers = 0

The moment i activate/ put worker >0 it does not work and did not produce failour count

as it not sharing login attempt counter between different process.


what is the alternative solution and is not possible to use login_cooldown_after in multithreading environment?

Avatar
Abbandona
Risposta migliore

odoo stores logins trials in registry so you can not guarantee which worker(process) the user will try each time. the best solution suggested from odoo use tool like fail2ban

source https://www.odoo.com/documentation/18.0/administration/on_premise/deploy.html#blocking-brute-force-attacks

Avatar
Abbandona
Autore

it means login_cooldown_after feature is useless!!