DNN does not apply rate limiting to incoming requests. The endpoint for requesting a password reset link accepted repeated consecutive requests, with the server returning an HTTP 200 response each time. No blocking, throttling, CAPTCHA, temporary lockout, or HTTP 429 "Too Many Requests" response was observed.
Is there a way to set a rate limit (retry limit) on password reset?
These Forums are for the discussion of the open source CMS DNN platform and ecosystem.
For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:
Awesome! Simply post in the forums using the link below and we'll get you started.