Rate limit login attempts per client address (closes #66)
check / check (push) Successful in 3m3s
check / check (push) Successful in 3m3s
POST / had no limit, so the signing key could be guessed at no cost. It is now limited to LoginAttemptsPerMinute (5) attempts per minute per client by a new RateLimit middleware on github.com/go-chi/httprate. It counts by the address the ClientIP middleware resolved through trusted_proxies, an IPv6 client by its /64, and answers an attempt over the limit with 429 and Retry-After. It runs after the body-size and CSRF checks, so every attempt that reaches the key comparison is counted. The image routes can reuse it. README states the limit; TODO narrows the per-IP item to the image routes. Model: opus-5-5
This commit is contained in:
@@ -100,6 +100,13 @@ than once, is refused with 400.
|
||||
- `<format>`: one of `orig`, `png`, `jpeg`, `webp`
|
||||
- `<size>`: `orig` or `<width>x<height>` (e.g. `800x600`)
|
||||
|
||||
The login form (`POST /`) is limited to 5 attempts per minute per client
|
||||
address, counting an IPv6 client by its /64; an attempt over the limit is
|
||||
refused with 429 and a `Retry-After` header. Behind a reverse proxy the client
|
||||
address comes from `X-Forwarded-For` only when the proxy's address is in
|
||||
`trusted_proxies`; otherwise all users behind the proxy are counted as one
|
||||
client.
|
||||
|
||||
### Source Hosts
|
||||
|
||||
Source hosts may be allowlisted in the configuration. Non-allowlisted
|
||||
|
||||
Reference in New Issue
Block a user