Skip to content

Brute force attack prevention #3479

Answered by balazsorban44
LNFWebsite asked this question in Help
Discussion options

You must be logged in to vote

The credentials provider is meant to be used with existing systems which we don't control. Those systems must take necessary measures themselves.

The functionality provided for credentials based authentication is intentionally limited to discourage use of passwords due to the inherent security risks associated with them and the additional complexity associated with supporting usernames and passwords

https://next-auth.js.org/providers/credentials

Replies: 3 comments 3 replies

Comment options

You must be logged in to vote
3 replies
@balazsorban44
Comment options

@LNFWebsite
Comment options

@LNFWebsite
Comment options

Answer selected by balazsorban44
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
4 participants