App-level persistent IP ban for Clusev's own login (distinct from the remote-fleet Fail2banService): BannedIp model, BruteforceGuard service, guests-only BlockBannedIp middleware, Login/2FA hooks + audit, a new Anmeldeschutz settings tab, clusev:unban CLI. Hardened after an adversarial multi-lens review: documented IP trust model (Caddy sole proxy, prod-only trustProxies), guests-only enforcement so an authed operator is never locked out and can self-unban, current-IP self-whitelist, concrete cache strategy, inet_pton CIDR matching, R5 confirm modals, errors.php for the 403 strings. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| 2026-06-14-account-recovery-design.md | ||
| 2026-06-14-accounts-sessions-restart-design.md | ||
| 2026-06-14-external-proxy-tls-design.md | ||
| 2026-06-14-optional-pluggable-2fa-design.md | ||
| 2026-06-14-server-details-hardening-polish-design.md | ||
| 2026-06-14-ssh-key-auto-provision-design.md | ||
| 2026-06-14-webauthn-yubikey-design.md | ||
| 2026-06-15-confirm-action-token-hardening-design.md | ||
| 2026-06-15-de-claude-history-rewrite-design.md | ||
| 2026-06-15-forgot-password-smtp-aware-design.md | ||
| 2026-06-15-installer-overhaul-design.md | ||
| 2026-06-15-recovery-codes-airtight-reveal-design.md | ||
| 2026-06-17-request-certificate-button-design.md | ||
| 2026-06-19-clusev-cli-and-command-shortcuts-design.md | ||
| 2026-06-19-help-page-design.md | ||
| 2026-06-20-2fa-challenge-backup-view-design.md | ||
| 2026-06-20-control-plane-bruteforce-ban-design.md | ||