If we get an account locked by exceeding the number of attempts, then wait for the lock expiration, the next login attempt will still display a message stating that the account is locked.
I'll open a PR to address this and also cleanup expired entries, to avoid accumulating data and bad usernames (e.g. ' OR 1=1; --).
PRs
If we get an account locked by exceeding the number of attempts, then wait for the lock expiration, the next login attempt will still display a message stating that the account is locked.
I'll open a PR to address this and also cleanup expired entries, to avoid accumulating data and bad usernames (e.g.
' OR 1=1; --).PRs