Page 1 of 1

Rename admin and limit failed logins

PostPosted: Thu Apr 01, 2010 10:07 am
by serond
Increase the logging to subsonic.log so It includes users logged in and failed tries with ip.

As techsc writes in this post: http://forum.subsonic.org/forum/viewtopic.php?t=2944
Security Policies should be implemented.

PostPosted: Sat Apr 03, 2010 12:52 am
by pufnstuf
yes please can we limit the number of times someone can fail logging in. I don't want people/bots to just hammer away at the login page until the manage to hit on the correct password.

Thanks for considering this! :)

PostPosted: Thu Apr 22, 2010 3:28 pm
by serond
Is there any plans of upgrading the security of subsoic?

http://en.wikipedia.org/wiki/Spring_Security

At present state it don't seem to log anything.