Rate limit password attempts on /metrics (closes #104)
check / check (push) Successful in 3m26s
check / check (push) Successful in 3m26s
Each client address may make 60 requests to /metrics a minute, through the same httprate middleware and TRUSTED_PROXIES resolution the report route uses, with an allowance of its own. The limit runs before the basic auth, so past it the answer is 429 and the password is not checked. backend/README.md says so; a test uses up one client's allowance on wrong passwords, gets 429 with the right one, and checks that another client behind the same nginx still gets in. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,13 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: password guesses at `/metrics` are rate limited (issue #104): each
|
||||
client address, resolved through `TRUSTED_PROXIES` as for reports, may make 60
|
||||
requests to `/metrics` a minute, counted by `go-chi/httprate` apart from its
|
||||
reports; past that it gets 429 and its basic auth credentials are not checked.
|
||||
The limit is a constant in `backend/internal/server/routes.go`. A test uses up
|
||||
one client's allowance on wrong passwords, gets 429 with the right one, and
|
||||
checks that another client behind the same nginx still gets in
|
||||
- 2026-10-04: the backend reports errors to Sentry (issue #95). With
|
||||
`SENTRY_DSN` set, it sets up `sentry-go` with the release `netwatch-server-`
|
||||
and its version, reports each panic in a handler through `sentryhttp`, the
|
||||
|
||||
Reference in New Issue
Block a user