Rate limit password attempts on /metrics #104

Closed
opened 2026-10-04 04:03:57 +02:00 by clawbot · 1 comment
Collaborator

Found by the review of #103 (Prometheus metrics, #94). Once that lands, GET /metrics checks a username and password with basic auth and nothing limits how fast a client can try passwords. REPO_POLICIES.md (Authentication and session security) asks for rate limiting on password-based authentication endpoints.

Definition of done

  • Requests to /metrics are rate limited per client address with github.com/go-chi/httprate, the decided package for HTTP rate limiting; over the limit, the answer is 429 and the password is not checked. The limit is a plain constant, generous enough for a scraper polling every few seconds.
  • The client address is the one nginx passes, not nginx's own loopback address, so one client cannot use up everyone's limit; say in the PR how that address reaches the backend.
  • A test: past the limit, 429; a different client address is not affected.
  • backend/README.md says /metrics is rate limited and to what.
  • After #94 lands. make check passes; TODO.md updated in the same commit; commit title ends (closes #N), with this issue's number.

Model: opus-5-5

Found by the review of https://git.eeqj.de/sneak/netwatch/pulls/103 (Prometheus metrics, https://git.eeqj.de/sneak/netwatch/issues/94). Once that lands, `GET /metrics` checks a username and password with basic auth and nothing limits how fast a client can try passwords. `REPO_POLICIES.md` (Authentication and session security) asks for rate limiting on password-based authentication endpoints. ## Definition of done - Requests to `/metrics` are rate limited per client address with `github.com/go-chi/httprate`, the decided package for HTTP rate limiting; over the limit, the answer is 429 and the password is not checked. The limit is a plain constant, generous enough for a scraper polling every few seconds. - The client address is the one nginx passes, not nginx's own loopback address, so one client cannot use up everyone's limit; say in the PR how that address reaches the backend. - A test: past the limit, 429; a different client address is not affected. - `backend/README.md` says `/metrics` is rate limited and to what. - After https://git.eeqj.de/sneak/netwatch/issues/94 lands. `make check` passes; `TODO.md` updated in the same commit; commit title ends ` (closes #N)`, with this issue's number. Model: opus-5-5
clawbot self-assigned this 2026-10-04 04:03:57 +02:00
Author
Collaborator

Implemented in #109: /metrics allows each client address 60 requests a minute, counted apart from reports, through the existing httprate middleware and client address handling; past that it answers 429 without checking the password. The PR says how the client address gets from nginx to the backend.

Model: opus-5-5

Implemented in https://git.eeqj.de/sneak/netwatch/pulls/109: `/metrics` allows each client address 60 requests a minute, counted apart from reports, through the existing `httprate` middleware and client address handling; past that it answers 429 without checking the password. The PR says how the client address gets from nginx to the backend. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#104