metrics: rate limit /metrics per client address before Basic Auth (closes #101)
check / check (push) Successful in 1m9s

/metrics is behind a password, and REPO_POLICIES.md requires rate
limiting on password logins. Each client address may now send it 30
requests a minute, counted by httprate before Basic Auth, so failed
logins use up the allowance and a request over it gets 429 without
the password being checked. The address is the one the existing
trusted-proxy logic in internal/middleware works out, with IPv6
addresses grouped by /64. A Prometheus server scraping every 15
seconds sends 4 requests a minute.

Model: opus-5-5
This commit is contained in:
2026-10-01 19:37:09 +00:00
parent 6070356676
commit c6f1943bb9
9 changed files with 271 additions and 4 deletions
+10
View File
@@ -0,0 +1,10 @@
package middleware
import "time"
// The /metrics rate limit, exported so the tests can count requests
// against it.
const (
MetricsRequestLimit = metricsRequestLimit
MetricsRequestWindow time.Duration = metricsRequestWindow
)