metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m9s
check / check (push) Successful in 1m9s
/metrics is behind a password, and REPO_POLICIES.md requires rate limiting on password logins. Each client address may now send it 30 requests a minute, counted by httprate before Basic Auth, so failed logins use up the allowance and a request over it gets 429 without the password being checked. The address is the one the existing trusted-proxy logic in internal/middleware works out, with IPv6 addresses grouped by /64. A Prometheus server scraping every 15 seconds sends 4 requests a minute. Model: opus-5-5
This commit is contained in:
@@ -20,6 +20,8 @@ https://git.eeqj.de/sneak/dnswatcher/issues/104
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-01: `/metrics` allows each client address 30 requests a minute,
|
||||
counted before Basic Auth, and answers 429 beyond that (closes #101).
|
||||
- 2026-10-01: `TODO.md` brought up to date: open issues listed by URL, every
|
||||
Completed Steps entry cut to at most two lines (closes #146).
|
||||
- 2026-10-01: wildcard CORS now applies only to the public routes, not to
|
||||
@@ -91,8 +93,6 @@ https://git.eeqj.de/sneak/dnswatcher/issues/104
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/107
|
||||
- invalid DNS or TLS interval silently replaced by the default:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/177
|
||||
- rate limit on `/metrics` Basic Auth:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/101
|
||||
- images report version `dev`: https://git.eeqj.de/sneak/dnswatcher/issues/109
|
||||
- trial run of the finished image:
|
||||
https://git.eeqj.de/sneak/dnswatcher/issues/149
|
||||
|
||||
Reference in New Issue
Block a user