What is Brute-Force Protection?
Defenses that slow or block repeated credential guessing: attempt counters, progressive delays, CAPTCHAs, and account lockouts. Effective setups throttle quietly while alerting on distributed patterns.
Related terms
Rate Limiting & HTTP 429
Server caps on request volume per client or key, answered with status 429 plus a Retry-After hint when exceeded. Limits protect login, signup, and AI endpoints from abuse and runaway costs.
Session vs Token Authentication
Server sessions store state behind an opaque cookie, while tokens carry signed claims the client presents each request. BYOB apps typically delegate both models to managed auth rather than hand-rolling stores.
Magic Link / OTP
Passwordless sign-in: the user receives an email link or one-time code instead of inventing a password. Fewer credentials to phish, fewer reset flows to build, higher conversion than passwords.
Cross-Site Request Forgery (CSRF)
An attack that tricks a logged-in browser into submitting unwanted state-changing requests to a trusted site. SameSite cookies, anti-CSRF tokens, and origin checks break the forgery chain.
SQL Injection
An attack that smuggles database commands through unsanitized input into application queries. Parameterized statements and least-privilege database roles keep hostile input as data, never executable code.
CSP Directives
The individual rules inside a Content Security Policy, such as script-src, object-src, and frame-ancestors. Each directive narrows one resource class, so auditing means reviewing directives one by one.