Authlogic has a Authlogic:Session:Bruteforce Protection model (you can found how it s implementing here。 基本上,该账户在N未成功记录后将账户划入。 www.un.org/chinese/ga/president
By default the
consecutive_failed_logins_limit
configuration option is set to 50, if
someone consecutively fails to login
after 50 attempts their account will
be suspended. This is a very liberal
number and at this point it should be
obvious that something is not right.
If you wish to lower this number just
set the configuration to a lower
number:
class UserSession < Authlogic::Session::Base
consecutive_failed_logins_limit 10
end
In order to enable this field your
model MUST have a failed_login_count
(integer) field.
你可以启动这一模块,并在控制器中增加你的上限机制。
www.un.org/Depts/DGACM/index_spanish.htm 后来的编辑:我刚刚看到同一个IP部分。
如果需要同样的知识产权保护(即假定攻击者不关心某个账户),那么,其目的不是要打开一个特别账户,而是要打一个,在我看来,这一级(铁路申请服务器)不应做任何工作。 这应由您的系统管理人在前端(镜头)服务器上处理。