Skip to content

Commit efeeabb

Browse files
skjnldsvclaude
andcommitted
docs(admin): warn that disabling bruteforcesettings app does not stop BFP
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Signed-off-by: skjnldsv <skjnldsv@protonmail.com>
1 parent e914f92 commit efeeabb

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

admin_manual/configuration_server/bruteforce_configuration.rst

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -172,6 +172,12 @@ Nextcloud's built-in brute force protection and fail2ban are complementary tools
172172
operate at different layers of the stack. Using both together is recommended for
173173
production servers.
174174

175+
.. warning::
176+
177+
Disabling the ``bruteforcesettings`` app does **not** disable brute force protection.
178+
The protection is built into Nextcloud Server core and is always active. The app only
179+
provides the admin UI and the IP exclusion settings.
180+
175181
**Nextcloud brute force protection** is built into Nextcloud Server itself (the
176182
``bruteforcesettings`` app provides the admin UI and exclusion settings, but the
177183
protection runs regardless). It works at the **application layer**: it detects

0 commit comments

Comments
 (0)