Skip to content
#

user-profile

Here are 65 public repositories matching this topic...

Laravel 8 with user authentication, registration with email confirmation, social media authentication, password recovery, and captcha protection. Uses offical [Bootstrap 4](http://getbootstrap.com). This also makes full use of Controllers for the routes, templates for the views, and makes use of middleware for routing. The project can be stood up in minutes.

  • Updated Sep 29, 2020
  • PHP
aeneasr
aeneasr commented Nov 17, 2020

Describe the bug

Currently, login requests will fail faster if the user does not exist as the hash does not have to be computed. This can leave to timing attacks where an attacker can guess if a user exists or not, which defeats account enumeration defenses.

Expected behavior

Every login request should take a similar amount of time regardless of whether the user exists or not. The

Improve this page

Add a description, image, and links to the user-profile topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the user-profile topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.