fix: Login with username (instead of email) (#19387)

This commit is contained in:
Dan Harrin
2026-03-02 14:49:53 +01:00
committed by GitHub
parent e3aef3418b
commit 0fd67ee602
2 changed files with 0 additions and 79 deletions
-24
View File
@@ -78,10 +78,6 @@ class Login extends SimplePage
$data = $this->form->getState();
if ($this->isLoginRateLimited($data['email'])) {
return null;
}
/** @var SessionGuard $authGuard */
$authGuard = Filament::auth();
@@ -164,26 +160,6 @@ class Login extends SimplePage
return false;
}
protected function isLoginRateLimited(string $email): bool
{
$rateLimitingKey = 'filament-login:' . sha1(request()->ip() . '|' . $email);
if (RateLimiter::tooManyAttempts($rateLimitingKey, maxAttempts: 5)) {
$this->getRateLimitedNotification(new TooManyRequestsException(
static::class,
'authenticate',
request()->ip(),
RateLimiter::availableIn($rateLimitingKey),
))?->send();
return true;
}
RateLimiter::hit($rateLimitingKey);
return false;
}
protected function getRateLimitedNotification(TooManyRequestsException $exception): ?Notification
{
return Notification::make()
-55
View File
@@ -215,61 +215,6 @@ it('can fill the login form, authenticate, and redirect to the dashboard in the
->assertNoAccessibilityIssues();
});
it('can throttle login attempts per IP and email', function (): void {
$this->assertGuest();
$userToAuthenticate = User::factory()->create();
// Clear the IP-only rate limiter between attempts to isolate the
// IP+email rate limit.
$clearIpRateLimiter = function (): void {
RateLimiter::clear('livewire-rate-limiter:' . sha1(Login::class . '|authenticate|' . request()->ip()));
};
foreach (range(1, 5) as $i) {
$clearIpRateLimiter();
livewire(Login::class)
->fillForm([
'email' => $userToAuthenticate->email,
'password' => 'password',
])
->call('authenticate');
$this->assertAuthenticated();
auth()->logout();
}
$clearIpRateLimiter();
// The 6th attempt from the same IP + email should be rate limited
livewire(Login::class)
->fillForm([
'email' => $userToAuthenticate->email,
'password' => 'password',
])
->call('authenticate')
->assertNotified();
$this->assertGuest();
$clearIpRateLimiter();
// A different email from the same IP should not be affected
$secondUser = User::factory()->create();
livewire(Login::class)
->fillForm([
'email' => $secondUser->email,
'password' => 'password',
])
->call('authenticate')
->assertRedirect(Filament::getUrl());
$this->assertAuthenticatedAs($secondUser);
});
it('does not lock out a user when an attacker exhausts login attempts from a different IP', function (): void {
$this->assertGuest();