|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L6 Presentation ยท Build flags: PROTOCORE_ENABLE_AUTH_LOCKOUT (requires PROTOCORE_ENABLE_AUTH, on by default)
This puts a per-source-IP guard in front of authenticated routes. After a few wrong passwords from one address, that address is locked out with exponential backoff and gets 429 Too Many Requests + Retry-After (without even checking credentials) instead of unlimited guesses. A correct login clears the address immediately. State lives in a fixed BSS table - no heap.
It is transparent to your route. You protect the route exactly as in BasicAuth; enabling the flag adds the lockout in front of the credential check automatically:
Tuning. The thresholds live in protocore_config.h: PROTOCORE_AUTH_LOCKOUT_THRESHOLD (failures before locking), PROTOCORE_AUTH_LOCKOUT_BASE_MS and PROTOCORE_AUTH_LOCKOUT_MAX_MS (the backoff window, which doubles per subsequent failure up to the max), and PROTOCORE_AUTH_LOCKOUT_SLOTS (how many addresses are tracked). Set them as build flags alongside the enable flag.
Build dependency. PROTOCORE_ENABLE_AUTH_LOCKOUT requires PROTOCORE_ENABLE_AUTH (which is on by default) - enforced by a compile-time #error.
The complete sketch (AuthLockout.ino), reproduced verbatim with added explanatory comments: