Highlights
Security fix: email codes now have an attempt limit when the realm has Brute Force Detection enabled (#146).
Before this release, turning on Brute Force Detection removed every limit on guessing an email code:
- Max code attempts was skipped whenever Brute Force Detection was on.
- From Keycloak 26.6, Keycloak also ignored wrong email codes, because it only counts failures from password, OTP and recovery-code steps.
So someone who already knew a user's password could keep guessing that user's code for its whole lifetime. Upgrading is recommended.
What changes, for Email OTP, Conditional Email OTP and Email OTP (No Enrollment):
- Max code attempts now applies whether or not Brute Force Detection is enabled. Once the limit is reached, the code is invalidated and the user must request a new one.
- With Brute Force Detection on, each wrong code also counts towards the realm's lockout:
- On Keycloak 26.6 and later, the extension reports it to Keycloak as an
otpfailure. - On 26.5 and earlier, Keycloak already counted it, so nothing changes there.
- On Keycloak 26.6 and later, the extension reports it to Keycloak as an
See Max code attempts for how the limit and the realm lockout work together.
Note
Changes admins may notice
- Users who mistype codes can now be temporarily locked out under the realm's Brute Force Detection settings, the same as for wrong passwords or TOTP codes.
- A correct email code now counts as an
otplogin. This resets the realm's OTP failure counter (maxSecondaryAuthFailures), so occasional typos don't add up to a permanent lockout. It also means a Condition - credential step set tootpnow matches users who signed in with an email code.
What's Changed
- fix: enforce max code attempts and count wrong codes when realm brute force protection is on by @ngineero in #162
- Release 26.7.1 by @github-actions[bot] in #163
New Contributors
Full Changelog: v26.7.0...v26.7.1