ArchitectureA supervised JVM-class runtime — OLTP on seven engines, OLAP on three. AI-native, MCP-native, observable as plain SQL.Read the architecture
Está viendo la edición Perú. Está viendo la edición Colombia. You're viewing the Pakistan edition. Cambiar a la edición global →Cambiar a la edición global →Switch to the global edition →

Login hardening: a TOTP second factor, failed-attempt delay, single-session mode

Time-based one-time passwords with QR enrolment, a delay after repeated failed logins, an option that keeps one session per user, and SAML, JWT and OAuth refinements for federated sign-in.

Password login is the surface every attacker tries first. This release adds the controls an auditor expects to find around it.

Controls on the form login

  • A second factor Time-based one-time passwords, enrolled from a QR code. A user's second factor can be reset, which invalidates the remembered-device cookies issued before the reset, and a failed code validation is slowed before it answers.
  • Throttling After three failed attempts for a user name, the next attempt is delayed, five seconds by default.
  • Single session An optional mode invalidates a user's other sessions on login, off by default.
  • No password, no form login A user with no stored password can only authenticate through an external provider.

Federated sign-in

  • SAML The name-identifier format is configurable per authenticator.
  • JWT A token is accepted from a configurable query parameter or cookie, with a flag that decides whether a session is created.
  • OAuth A logout endpoint redirects to the identity provider so the session ends on both sides.

Later releases moved the password hash to Argon2id, added the breach check on password change and risk-based login. This is the baseline they build on.