diff --git a/backend/src/middlewares/auth.middleware.ts b/backend/src/middlewares/auth.middleware.ts index bf22e33..9e77de8 100644 --- a/backend/src/middlewares/auth.middleware.ts +++ b/backend/src/middlewares/auth.middleware.ts @@ -217,8 +217,9 @@ const getAuthenticatedUserOrAnonymous = async (req: Request): Promise => { // Limit login attempts to avoid brute force attacks const loginLimiter = rateLimit({ - windowMs: ms('15m'), + windowMs: ms('5m'), limit: 5, + skipSuccessfulRequests: true, message: 'Too many login attempts, please try again later' });