Rate limit login attempts per client address (closes #66)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
POST / had no limit, so the signing key could be guessed at no cost. It is now limited to 5 attempts per minute per client by a new RateLimit middleware on github.com/go-chi/httprate; an attempt over the limit gets 429 with Retry-After. It counts by the address the ClientIP middleware resolved through trusted_proxies (an IPv4-mapped address as its IPv4 address, IPv6 by its /64) and runs after the body-size and CSRF checks, so every attempt that reaches the key comparison is counted. README says that with the default trusted_proxies a client with a private address can choose its counted address, and how to close that. Model: opus-5-5
This commit was merged in pull request #143.
This commit is contained in:
@@ -100,6 +100,17 @@ than once, is refused with 400.
|
||||
- `<format>`: one of `orig`, `png`, `jpeg`, `webp`
|
||||
- `<size>`: `orig` or `<width>x<height>` (e.g. `800x600`)
|
||||
|
||||
The login form (`POST /`) is limited to 5 attempts per minute per client
|
||||
address, counting an IPv6 client by its /64; an attempt over the limit is
|
||||
refused with 429 and a `Retry-After` header. Behind a reverse proxy the client
|
||||
address comes from `X-Forwarded-For` only when the proxy's address is in
|
||||
`trusted_proxies`; otherwise all users behind the proxy are counted as one
|
||||
client. With the default `trusted_proxies` (the RFC 1918 ranges), a client
|
||||
with a private address can choose the address it is counted by through its own
|
||||
`X-Forwarded-For`, whether it connects directly or through the proxy, because
|
||||
its own address is trusted too. Setting `trusted_proxies` to the proxy's own
|
||||
address closes this.
|
||||
|
||||
### Source Hosts
|
||||
|
||||
Source hosts may be allowlisted in the configuration. Non-allowlisted
|
||||
@@ -205,7 +216,8 @@ Key settings in more detail:
|
||||
inside one of these ranges; the logged and login-recorded client
|
||||
address is then the rightmost forwarded entry that is not itself a
|
||||
trusted proxy. Otherwise the direct peer address is used and the header
|
||||
is ignored, so a client connecting directly cannot spoof its address.
|
||||
is ignored, so a client connecting directly from an address outside
|
||||
these ranges cannot spoof its address.
|
||||
An omitted key defaults to the RFC 1918 private ranges (`10.0.0.0/8`,
|
||||
`172.16.0.0/12`, `192.168.0.0/16`), since pixa is deployed behind a
|
||||
proxy on a private network; an explicitly empty list (`[]`) trusts no
|
||||
|
||||
Reference in New Issue
Block a user