Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cognito AAI TF: Enabled new feature prevent_user_existence_errors check #415

Merged

Conversation

victorskl
Copy link
Member

  • This new feature flag is a good thing. It prevents attack surface that
    potentially brute-force scanning user existence to our Cognito instance.
  • Added notes about token revocation

…heck

* This new feature flag is a good thing. It prevents attack surface that
  potentially brute-force scanning user existence to our Cognito instance.
* Added notes about token revocation
@victorskl victorskl self-assigned this Apr 11, 2024
@victorskl victorskl added the feature New feature or request label Apr 11, 2024
@victorskl
Copy link
Member Author

Related umccr/orcabus#214

@victorskl victorskl added this to the 202N.0N milestone May 17, 2024
Copy link
Member

@reisingerf reisingerf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good!
I think the refresh token validity is long enough to make this useful.

@victorskl victorskl merged commit 7597fa3 into master May 20, 2024
1 check passed
@victorskl victorskl deleted the cognito-aai-enable-user-existence-throttling-feature branch May 20, 2024 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants