Skip to content

feat(auth): account lockout after failed login — Issue #805 - #995

Merged
github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-805-account-lockout
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-805-account-lockout

Conversation

@Prozaks

@Prozaks Prozaks commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

Implements the account lockout route and comprehensive tests for Issue #805.

Existing lockout infrastructure:

  • src/services/account-lockout.ts — Redis-based AccountLockoutService
  • src/services/auth/lockout-manager.ts — In-memory LockoutManager
  • src/middleware/auth-lockout.ts — Express middleware

New files

src/routes/auth-lockout.ts

A dedicated REST API for lockout management:

  • GET /auth/lockout/status/:identifier — check lockout state
  • POST /auth/lockout/attempt — record a login attempt (success or failure)
  • POST /auth/lockout/unlock/:accountId — admin unlock with optional token
  • GET /auth/lockout/attempts — list recent attempts
  • DELETE /auth/lockout/clear/:identifier — clear lockout state

Tests

  • src/routes/__tests__/auth-lockout.test.ts — route + LockoutManager integration tests
  • src/services/__tests__/account-lockout.test.ts — AccountLockoutService unit tests (Redis mock)

Test results

Test Files  2 passed
     Tests  38 passed
  Duration  ~1.6s

Closes #805

@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks is attempting to deploy a commit to the smartdevs17's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@github-actions
github-actions Bot merged commit d850bb7 into Smartdevs17:main Sep 28, 2026
14 of 25 checks passed
- Add auth-lockout route with 5 endpoints:
  GET  /auth/lockout/status/:identifier
  POST /auth/lockout/attempt
  POST /auth/lockout/unlock/:accountId
  GET  /auth/lockout/attempts
  DELETE /auth/lockout/clear/:identifier
- Add tests for route handlers (LockoutManager integration)
- Add tests for AccountLockoutService (Redis-based) covering:
  progressive delays, lockout threshold, clearLockout,
  isAllowedToAttempt with all paths

Closes Smartdevs17#805
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add account lockout after failed login attempts

1 participant