diff --git a/backend/models/User.js b/backend/models/User.js index bb62342..a875a8b 100644 --- a/backend/models/User.js +++ b/backend/models/User.js @@ -176,7 +176,7 @@ User.prototype.comparePassword = async function (password) { }; // Account lockout constants -const MAX_LOGIN_ATTEMPTS = 5; +const MAX_LOGIN_ATTEMPTS = 10; const LOCK_TIME = 2 * 60 * 60 * 1000; // 2 hours // Check if account is locked diff --git a/backend/routes/auth.js b/backend/routes/auth.js index 95fb738..e214a5e 100644 --- a/backend/routes/auth.js +++ b/backend/routes/auth.js @@ -215,7 +215,7 @@ router.post( if (user.isLocked()) { return res.status(423).json({ error: - "Account is temporarily locked due to too many failed login attempts. Please try again later.", + "Account is temporarily locked due to too many failed login attempts. Please try again in 2 hours.", }); }