Feature request · Permissions & security · Blocks work
Return HTTP 401 on failed logins so Fail2Ban can block attackers
1 source thread · first seen 2019-11
Summary
Failed logins currently return HTTP 400, making it hard to write a Fail2Ban filter; the requester asks for 401 as the API docs suggest.
- Affects
- Self-hosting admin
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Could it then be possible to return HTTP/401 in case of wrong username / password please ?”