1. Go to this page and download the library: Download lara-care/account-lockout library. Choose the download type require.
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
lara-care / account-lockout example snippets
return [
/*
|--------------------------------------------------------------------------
| Max Login Attempts
|--------------------------------------------------------------------------
|
| Maximum number of failed attempts allowed before triggering a lockout.
|
*/
'max_attempts' => 5,
/*
|--------------------------------------------------------------------------
| Progressive Decay Minutes
|--------------------------------------------------------------------------
|
| Cooldown periods (in minutes) for consecutive lockouts.
|
*/
'cooldown_penalties' => [
1 => 15, // First lockout: 15 minutes
2 => 60, // Second lockout: 60 minutes
3 => 1440 // Third lockout: 24 hours
],
];
use LaraCare\AccountLockout\Services\LockoutManager;
class LoginController extends Controller
{
public function login(Request $request, LockoutManager $lockout)
{
$user = User::where('email', $request->email)->first();
// Check if the user is currently locked out
if ($user && $lockout->isLocked($user)) {
return response()->json([
'message' => 'Your account is locked due to multiple failed login attempts.'
], 423);
}
if (! Auth::attempt($request->only('email', 'password'))) {
if ($user) {
// Record the failed attempt
$lockout->recordFailedAttempt($user, $request->ip());
}
return response()->json(['message' => 'Invalid credentials.'], 401);
}
// Reset lockout count on successful login
$lockout->unlock($user);
return response()->json(['message' => 'Login successful.']);
}
}