Overslaan naar inhoud
Menu
Je moet geregistreerd zijn om te kunnen communiceren met de community.
Deze vraag is gerapporteerd
1 Beantwoorden
320 Weergaven

To secure production enviornment from Brute force attack Odoo has implemented login_cooldown_after

It working fine when workers = 0

The moment i activate/ put worker >0 it does not work and did not produce failour count

as it not sharing login attempt counter between different process.


what is the alternative solution and is not possible to use login_cooldown_after in multithreading environment?

Avatar
Annuleer
Beste antwoord

odoo stores logins trials in registry so you can not guarantee which worker(process) the user will try each time. the best solution suggested from odoo use tool like fail2ban

source https://www.odoo.com/documentation/18.0/administration/on_premise/deploy.html#blocking-brute-force-attacks

Avatar
Annuleer
Auteur

it means login_cooldown_after feature is useless!!