fix: correct login rate limiter key format to include IP address

This commit is contained in:
Andras Bacsai 2025-10-28 10:32:19 +01:00
parent f300ba0118
commit 65e5b2ecdb

View file

@ -139,7 +139,7 @@ public function boot(): void
// server('REMOTE_ADDR') gives the actual connecting IP before proxy headers
$realIp = $request->server('REMOTE_ADDR') ?? $request->ip();
return Limit::perMinute(5)->by($email.$realIp);
return Limit::perMinute(5)->by($email.'|'.$realIp);
});
RateLimiter::for('two-factor', function (Request $request) {