Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions config/auth.php
Original file line number Diff line number Diff line change
Expand Up @@ -24,12 +24,24 @@
| 'table' — the users table each guard authenticates against.
| 'username' — the column checked against the login credential (session
| guard only; e.g. change to 'username' for a non-email login).
| 'throttle' — (session guard only) lockout after repeated failed
| attempts against the *same* login identifier, regardless
| of the attacker's IP — defends one account against
| credential stuffing distributed across many addresses,
| which an IP-keyed `throttle:` route middleware won't
| catch. Only failed attempts count; a correct password
| never gets throttled. Defaults to 5 attempts / 60s if
| omitted.
*/
'guards' => [
'session' => [
'driver' => 'session',
'table' => 'users',
'username' => 'email',
'throttle' => [
'max_attempts' => (int) env('AUTH_THROTTLE_MAX_ATTEMPTS', 5),
'decay_seconds' => (int) env('AUTH_THROTTLE_DECAY_SECONDS', 60),
],
],
'jwt' => [
'driver' => 'jwt',
Expand All @@ -39,4 +51,16 @@
],
],

/*
|--------------------------------------------------------------------------
| Redirects
|--------------------------------------------------------------------------
| 'login' — where the `auth` middleware (Marrow\Middleware\Authenticate)
| sends an unauthenticated web request. Only consulted for
| non-JSON requests; a JSON/API request gets a 401 instead.
*/
'redirects' => [
'login' => '/login',
],

];
Loading