Document that credentials are accepted only in a URL-encoded body

This commit is contained in:
Viktor Liu
2026-09-23 13:19:36 +02:00
parent 469973f59d
commit d01b6089c4
+5 -2
View File
@@ -1,7 +1,10 @@
# PIN and password authentication limits # PIN and password authentication limits
PIN and password credentials are accepted only in a POST form body. Query-string PIN and password credentials are accepted only in a URL-encoded
credentials and credentials on other HTTP methods are ignored. (`application/x-www-form-urlencoded`) POST body. Query-string credentials,
multipart and other body encodings, and credentials on other HTTP methods are
ignored. The encoding is restricted because it is the one AppSec inspection can
redact before mirroring a request to the engine.
The proxy permits a burst of five credential checks per account and service, The proxy permits a burst of five credential checks per account and service,
then replenishes one check every six seconds (ten per minute). PIN and password then replenishes one check every six seconds (ten per minute). PIN and password