Rate limit login attempts per client address (closes #66)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
POST / had no limit, so the signing key could be guessed at no cost. It is now limited to 5 attempts per minute per client by a new RateLimit middleware on github.com/go-chi/httprate; an attempt over the limit gets 429 with Retry-After. It counts by the address the ClientIP middleware resolved through trusted_proxies (an IPv4-mapped address as its IPv4 address, IPv6 by its /64) and runs after the body-size and CSRF checks, so every attempt that reaches the key comparison is counted. README says that with the default trusted_proxies a client with a private address can choose its counted address, and how to close that. Model: opus-5-5
This commit was merged in pull request #143.
This commit is contained in:
@@ -30,6 +30,15 @@ exhaustion
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-28 rate limit the login form (closes #66): `POST /` is limited to 5
|
||||
attempts per minute per client address, and an attempt over the limit is
|
||||
refused with 429 and a `Retry-After` header; the address is the one
|
||||
`internal/clientip` resolves through `trusted_proxies`, an IPv6 client is
|
||||
counted by its /64, and an IPv4-mapped address as the IPv4 address it
|
||||
carries; the limit is a `RateLimit` middleware in `internal/middleware` on
|
||||
`github.com/go-chi/httprate`, which the image routes can reuse; the library
|
||||
keeps counts for the current and the previous minute only; documented in
|
||||
`README.md`.
|
||||
- 2026-09-28 refuse an unparseable `exp` on `/v1/image/` and log swallowed
|
||||
cache errors (closes #72): an `exp` in the URL that is not a whole
|
||||
number, an empty `exp=` included, is a 400 naming `exp` and the value,
|
||||
@@ -245,7 +254,7 @@ exhaustion
|
||||
- P1: strip EXIF and other metadata from processed images (privacy)
|
||||
- P2: security
|
||||
- referer blacklist
|
||||
- per-IP rate limiting
|
||||
- per-IP rate limiting on the image routes
|
||||
- per-origin rate limiting
|
||||
- P2: HTTP response handling
|
||||
- Last-Modified headers
|
||||
|
||||
Reference in New Issue
Block a user