check / check (push) Successful in 1m9s
/metrics is behind a password, and REPO_POLICIES.md requires rate limiting on password logins. Each client address may now send it 30 requests a minute, counted by httprate before Basic Auth, so failed logins use up the allowance and a request over it gets 429 without the password being checked. The address is the one the existing trusted-proxy logic in internal/middleware works out, with IPv6 addresses grouped by /64. A Prometheus server scraping every 15 seconds sends 4 requests a minute. Model: opus-5-5
11 lines
246 B
Go
11 lines
246 B
Go
package middleware
|
|
|
|
import "time"
|
|
|
|
// The /metrics rate limit, exported so the tests can count requests
|
|
// against it.
|
|
const (
|
|
MetricsRequestLimit = metricsRequestLimit
|
|
MetricsRequestWindow time.Duration = metricsRequestWindow
|
|
)
|