While more of an annoyance than a security issue, I have had some users spam password reset requests to everyone they can find. The module should track password reset attempts and be included in the blocks.

Comments

ilo’s picture

Status: Active » Postponed (maintainer needs more info)

This requires a different tracking table, however I agree with you, this can be addressed with the new feature list. Postponed for now, don't want to forget it.

deekayen’s picture

Version: 6.x-1.x-dev » 7.x-1.x-dev
Status: Postponed (maintainer needs more info) » Active

bumping version

rooby’s picture

Related issue for drupal core #1681832: Password reset form has no flood protection

Seems like that eventually might get into drupal 7 core.