Refuse image requests whose Referer is on referer_blocklist (closes #90)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
A new setting, referer_blocklist (PIXA_REFERER_BLOCKLIST), lists hosts whose pages may not show pixa's images. Entries are written and matched as allowlist_hosts are, with the same matcher. Both image routes check the Referer before the signature, the cache and the upstream fetch, and answer 403 with the JSON error, so a blocked request costs nothing and is refused whether or not the image is cached. No Referer, or one that does not parse, is served; README.md says this makes the list easy to get around. An entry of either host list that is not a host name (letters, digits, hyphens, underscores, dots, at most one leading dot) or an IP address now aborts startup naming the setting and the entry. Model: opus-5-5
This commit was merged in pull request #197.
This commit is contained in:
@@ -27,10 +27,22 @@ The disk cache is now size-bounded with LRU eviction
|
||||
|
||||
# Next Step
|
||||
|
||||
P2: security: referer blacklist
|
||||
P2: security: per-IP rate limiting on the image routes
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04 referer blocklist (closes #90): `referer_blocklist`
|
||||
(`PIXA_REFERER_BLOCKLIST`) lists hosts, written and matched as for
|
||||
`allowlist_hosts` with the same matcher; an entry of either list that is
|
||||
neither a host name (letters, digits, hyphens, underscores and dots, with at
|
||||
most one leading dot) nor an IP address, such as one with a port or a `*.`
|
||||
wildcard, aborts startup naming the setting and the entry. Both image routes
|
||||
refuse a request whose `Referer` names a listed host with 403 and a JSON error
|
||||
before the signature, the cache and the upstream fetch, so it fetches nothing
|
||||
and is refused whether or not the image is cached. A request with no
|
||||
`Referer`, or one that does not parse as a URL with a host, is served, so the
|
||||
list is easily got around; `README.md` and `configs/config.example.yml` say
|
||||
so. It does not apply to the login and generator pages.
|
||||
- 2026-10-04 fewer files in the repository root (closes #97):
|
||||
`config.example.yml` moved unchanged to `configs/config.example.yml`, and
|
||||
`README.md`, the comments in `internal/config/config.go` and the startup error
|
||||
@@ -561,7 +573,6 @@ P2: security: referer blacklist
|
||||
# Future Steps
|
||||
|
||||
- P2: security
|
||||
- per-IP rate limiting on the image routes
|
||||
- per-origin rate limiting
|
||||
- P2: HTTP response handling
|
||||
- Last-Modified headers
|
||||
|
||||
Reference in New Issue
Block a user