Details
Description
When ACL rules block registration they respond with a 403 Forbidden when the username matches and with 401 Unauthorized when the username does not match.
This essentially allows someone to constantly test usernames and see which ones are valid and which ones are not.
I've only encountered this problem on my setup working with Realtime. Not sure what else is effected.
Issue Links
- is a clone of
-
SWP-10304 Loading...
Thanks for creating a report! The issue has entered the triage process. That means the issue will wait in this status until a Bug Marshal has an opportunity to review the issue. Once the issue has been reviewed you will receive comments regarding the next steps towards resolution.
A good first step is for you to review the Asterisk Issue Guidelines if you haven't already. The guidelines detail what is expected from an Asterisk issue report.
Then, if you are submitting a patch, please review the Patch Contribution Process.