Friction

Feature request · Permissions & security · Blocks work

Return HTTP 401 on failed logins so Fail2Ban can block attackers

1 source thread · first seen 2019-11

Summary

Failed logins currently return HTTP 400, making it hard to write a Fail2Ban filter; the requester asks for 401 as the API docs suggest.

Affects
Self-hosting admin

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Could it then be possible to return HTTP/401 in case of wrong username / password please ?”

Report this item