Found by the review of #103 (Prometheus metrics, #94). Once that lands, GET /metrics checks a username and password with basic auth and nothing limits how fast a client can try passwords. REPO_POLICIES.md (Authentication and session security) asks for rate limiting on password-based authentication endpoints.
Definition of done
Requests to /metrics are rate limited per client address with github.com/go-chi/httprate, the decided package for HTTP rate limiting; over the limit, the answer is 429 and the password is not checked. The limit is a plain constant, generous enough for a scraper polling every few seconds.
The client address is the one nginx passes, not nginx's own loopback address, so one client cannot use up everyone's limit; say in the PR how that address reaches the backend.
A test: past the limit, 429; a different client address is not affected.
backend/README.md says /metrics is rate limited and to what.
After #94 lands. make check passes; TODO.md updated in the same commit; commit title ends (closes #N), with this issue's number.
Model: opus-5-5
Found by the review of https://git.eeqj.de/sneak/netwatch/pulls/103 (Prometheus metrics, https://git.eeqj.de/sneak/netwatch/issues/94). Once that lands, `GET /metrics` checks a username and password with basic auth and nothing limits how fast a client can try passwords. `REPO_POLICIES.md` (Authentication and session security) asks for rate limiting on password-based authentication endpoints.
## Definition of done
- Requests to `/metrics` are rate limited per client address with `github.com/go-chi/httprate`, the decided package for HTTP rate limiting; over the limit, the answer is 429 and the password is not checked. The limit is a plain constant, generous enough for a scraper polling every few seconds.
- The client address is the one nginx passes, not nginx's own loopback address, so one client cannot use up everyone's limit; say in the PR how that address reaches the backend.
- A test: past the limit, 429; a different client address is not affected.
- `backend/README.md` says `/metrics` is rate limited and to what.
- After https://git.eeqj.de/sneak/netwatch/issues/94 lands. `make check` passes; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`, with this issue's number.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 04:03:57 +02:00
Implemented in #109: /metrics allows each client address 60 requests a minute, counted apart from reports, through the existing httprate middleware and client address handling; past that it answers 429 without checking the password. The PR says how the client address gets from nginx to the backend.
Model: opus-5-5
Implemented in https://git.eeqj.de/sneak/netwatch/pulls/109: `/metrics` allows each client address 60 requests a minute, counted apart from reports, through the existing `httprate` middleware and client address handling; past that it answers 429 without checking the password. The PR says how the client address gets from nginx to the backend.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by the review of #103 (Prometheus metrics, #94). Once that lands,
GET /metricschecks a username and password with basic auth and nothing limits how fast a client can try passwords.REPO_POLICIES.md(Authentication and session security) asks for rate limiting on password-based authentication endpoints.Definition of done
/metricsare rate limited per client address withgithub.com/go-chi/httprate, the decided package for HTTP rate limiting; over the limit, the answer is 429 and the password is not checked. The limit is a plain constant, generous enough for a scraper polling every few seconds.backend/README.mdsays/metricsis rate limited and to what.make checkpasses;TODO.mdupdated in the same commit; commit title ends(closes #N), with this issue's number.Model: opus-5-5
clawbot referenced this issue2026-10-04 04:59:08 +02:00
Implemented in #109:
/metricsallows each client address 60 requests a minute, counted apart from reports, through the existinghttpratemiddleware and client address handling; past that it answers 429 without checking the password. The PR says how the client address gets from nginx to the backend.Model: opus-5-5