fix(auth): flexibilizar login por email/usuario, asegurar hash admin123 y corregir cookies sobre HTTP

This commit is contained in:
2026-09-23 14:59:46 -03:00
parent bddd382c96
commit b540015b7e
7 changed files with 47 additions and 20 deletions
+8 -4
View File
@@ -40,17 +40,20 @@ const app = express();
const port = process.env.PORT || 3000;
app.disable('x-powered-by');
app.set('trust proxy', 1);
// Blindaje HTTP con Helmet
// Blindaje HTTP con Helmet (compatible con despliegues directos por IP y proxies HTTPS)
app.use(helmet({
contentSecurityPolicy: false,
crossOriginEmbedderPolicy: false
crossOriginEmbedderPolicy: false,
crossOriginOpenerPolicy: false,
originAgentCluster: false
}));
// Rate Limiting para protección contra ataques de fuerza bruta y abuso
const authLimiter = rateLimit({
windowMs: 15 * 60 * 1000,
max: 30,
max: 60,
message: 'Demasiados intentos de autenticación. Por favor intente nuevamente en 15 minutos.',
standardHeaders: true,
legacyHeaders: false
@@ -61,7 +64,8 @@ const generalLimiter = rateLimit({
standardHeaders: true,
legacyHeaders: false
});
app.use('/auth/login', authLimiter);
app.post('/auth/login', authLimiter);
app.post('/auth/moodle', authLimiter);
app.use('/api', generalLimiter);
// Configuración de middlewares