Six months after the second factor and the failed-attempt delay, the login surface gained its next layer: limits that hold under distributed attack, a separate door for administrators, and a way to write an authenticator without a Java release.
Limits and sessions
- Rate limits in the handler A limiter by IP and by user is integrated into the web security handler, replacing a standalone filter; the block list can be read as a result set.
- Session fixation closed The session id is regenerated on login.
- Failures recorded Each failed attempt is logged with its request details, the last login date is kept on the user, and users see their own failed attempts from the toolbar menu.
Doors
- An administrator login A dedicated page and login type, protected by a CSRF token. A cookie remembers the last mode used.
- Custom authenticators Authenticator logic can be written in JavaScript and stored in the configuration database.
Risk-based login, with a score and forced second factor, followed in 2026 on this foundation.