Add explicit login functionality
This commit is contained in:
@@ -38,7 +38,7 @@ func (s *Server) handleDelete(w http.ResponseWriter, r *http.Request) {
|
||||
// Only failures are throttled, so a correct token is never delayed.
|
||||
// The info page is publicly shareable and now carries a credential
|
||||
// field, which is reason enough not to let it be hammered freely.
|
||||
if !s.deleteLimiter.allow(clientIP(r, s.cfg), s.now()) {
|
||||
if !s.authLimiter.allow(clientIP(r, s.cfg), s.now()) {
|
||||
s.refuse(w, r, m, from, http.StatusTooManyRequests,
|
||||
"Too many failed attempts; try again shortly.")
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user