diff options
author | Robin Appelman <robin@icewind.nl> | 2016-08-26 15:10:03 +0200 |
---|---|---|
committer | Robin Appelman <robin@icewind.nl> | 2016-08-29 13:36:49 +0200 |
commit | 6c93fe08f53bff474921d150edabb27ca630edd7 (patch) | |
tree | afdc87fb14c91e0dbc71b32e7f8c5abbb70e40e6 /lib | |
parent | 3647fbe7cd86e743b059889d69b03fcf8207780f (diff) | |
download | nextcloud-server-6c93fe08f53bff474921d150edabb27ca630edd7.tar.gz nextcloud-server-6c93fe08f53bff474921d150edabb27ca630edd7.zip |
dont get bruteforce delay twice
Diffstat (limited to 'lib')
-rw-r--r-- | lib/private/Security/Bruteforce/Throttler.php | 5 | ||||
-rw-r--r-- | lib/private/User/Session.php | 3 |
2 files changed, 5 insertions, 3 deletions
diff --git a/lib/private/Security/Bruteforce/Throttler.php b/lib/private/Security/Bruteforce/Throttler.php index 11a343918c6..031c5ffd411 100644 --- a/lib/private/Security/Bruteforce/Throttler.php +++ b/lib/private/Security/Bruteforce/Throttler.php @@ -225,8 +225,11 @@ class Throttler { * Will sleep for the defined amount of time * * @param string $ip + * @return int the time spent sleeping */ public function sleepDelay($ip) { - usleep($this->getDelay($ip) * 1000); + $delay = $this->getDelay($ip); + usleep($delay * 1000); + return $delay; } } diff --git a/lib/private/User/Session.php b/lib/private/User/Session.php index 3b357b69bcf..dec959820f8 100644 --- a/lib/private/User/Session.php +++ b/lib/private/User/Session.php @@ -309,8 +309,7 @@ class Session implements IUserSession, Emitter { $password, IRequest $request, OC\Security\Bruteforce\Throttler $throttler) { - $currentDelay = $throttler->getDelay($request->getRemoteAddress()); - $throttler->sleepDelay($request->getRemoteAddress()); + $currentDelay = $throttler->sleepDelay($request->getRemoteAddress()); $isTokenPassword = $this->isTokenPassword($password); if (!$isTokenPassword && $this->isTokenAuthEnforced()) { |