Rate limit password attempts on /metrics (closes #104) #109

Merged
clawbot merged 1 commits from issue-104-metrics-rate-limit into next 2026-10-04 06:19:07 +02:00
1 Commits
Author SHA1 Message Date
sneak 5f39597eae Rate limit password attempts on /metrics (closes #104)
check / check (push) Waiting to run
Each client address may make 60 requests to /metrics a minute,
through the same httprate middleware and TRUSTED_PROXIES
resolution the report route uses, with an allowance of its own.
The limit runs before the basic auth, so past it the answer is 429
and the password is not checked. backend/README.md says so; a test
uses up one client's allowance on wrong passwords, gets 429 with
the right one, and checks that another client behind the same
nginx still gets in.

Model: opus-5-5
2026-10-04 04:01:37 +00:00