You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, when in a realm the password + internal provider are set and enabled, the password registration form (when enabled) does not include any mitigation against bot attempting to register a multitude of users in an automated way.
While the newly created users are not confirmed and usable, they might do still occupy backend resources for some amount of time.
A possible solution against such a scenario could be to optionally include a captcha in the registration form, where the option to include the captcha or not is provided in the admin console for that provider.
The text was updated successfully, but these errors were encountered:
thomaschiozzi-tndigit
changed the title
Bot registering fake users prevention measure
Prevention measure against bot registering fake users
Feb 2, 2024
Currently, when in a realm the password + internal provider are set and enabled, the password registration form (when enabled) does not include any mitigation against bot attempting to register a multitude of users in an automated way.
While the newly created users are not confirmed and usable, they might do still occupy backend resources for some amount of time.
A possible solution against such a scenario could be to optionally include a captcha in the registration form, where the option to include the captcha or not is provided in the admin console for that provider.
The text was updated successfully, but these errors were encountered: