diff --git a/files/routes/login.py b/files/routes/login.py index 48dedfcc8..92b4a26a6 100644 --- a/files/routes/login.py +++ b/files/routes/login.py @@ -37,9 +37,10 @@ def login_deduct_when(resp): return g.login_failed @app.post("/login") +@auth_desired @limiter.limit("6/minute;10/day", deduct_when=login_deduct_when) -def login_post(): - template = '' +def login_post(v:Optional[User]): + if v: abort(400) g.login_failed = True username = request.values.get("username")