mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2025-08-24 11:43:19 +00:00
parent
2a5489a4b2
commit
ae7b725c0f
1 changed files with 1 additions and 1 deletions
|
@ -571,7 +571,7 @@
|
|||
##
|
||||
## According to the RFC6238 (https://tools.ietf.org/html/rfc6238),
|
||||
## we allow by default the TOTP code which was valid one step back and one in the future.
|
||||
## This can however allow attackers to be a bit more lucky with there attempts because there are 3 valid codes.
|
||||
## This can however allow attackers to be a bit more lucky with their attempts because there are 3 valid codes.
|
||||
## You can disable this, so that only the current TOTP Code is allowed.
|
||||
## Keep in mind that when a sever drifts out of time, valid codes could be marked as invalid.
|
||||
## In any case, if a code has been used it can not be used again, also codes which predates it will be invalid.
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue