API Docs improvements, lockouts fixed, security and speed
We've released a few fixes in the last week or two and none were big enough to justify their own post, so here's the roundup.
- The Public API docs didn't document errors very well (or at all in some cases) so you had no way to know why a call might fail. We fixed that, the docs now tell you all the failure modes and what to do with them. 📋
- We fixed an issue where if you were locked out of your account due to too many incorrect login attempts you couldn't get back in if you didn't get the password right first time. Sorry about that - we reset all lockouts at the time and we've got alerting on them now so we can see if there's an issue going forward ✅
- We've brought the backend right up to date which has brought the usual raft of security and speed fixes. ⬆️
- Quite a few security things have been improved, we've been really tightening down on edge cases with improvements to account enumeration prevention, better rate limits, smoother login flow for incorrect passwords/2fa, tighter access controls on email verification emails 🔐
- We've done a whole raft of improvements to performance which should result in speedier email summaries, general email delivery, loading of the Wallchart and loads of other places throughout the app. ⚡