Rate limit login attempts per client address (closes #66)
check / check (push) Successful in 3m3s

POST / had no limit, so the signing key could be guessed at no cost. It
is now limited to LoginAttemptsPerMinute (5) attempts per minute per
client by a new RateLimit middleware on github.com/go-chi/httprate. It
counts by the address the ClientIP middleware resolved through
trusted_proxies, an IPv6 client by its /64, and answers an attempt over
the limit with 429 and Retry-After. It runs after the body-size and CSRF
checks, so every attempt that reaches the key comparison is counted. The
image routes can reuse it. README states the limit; TODO narrows the
per-IP item to the image routes.

Model: opus-5-5
This commit is contained in:
2026-09-28 21:22:25 +00:00
parent 1a50dd20d9
commit e6c326fc96
6 changed files with 53 additions and 2 deletions
+3
View File
@@ -11,6 +11,7 @@ require (
github.com/getsentry/sentry-go v0.40.0
github.com/go-chi/chi/v5 v5.2.3
github.com/go-chi/cors v1.2.2
github.com/go-chi/httprate v0.16.0
github.com/gorilla/csrf v1.7.3
github.com/gorilla/securecookie v1.1.2
github.com/prometheus/client_golang v1.23.2
@@ -91,6 +92,7 @@ require (
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/josharian/intern v1.0.0 // indirect
github.com/json-iterator/go v1.1.12 // indirect
github.com/klauspost/cpuid/v2 v2.2.10 // indirect
github.com/kylelemons/godebug v1.1.0 // indirect
github.com/mailru/easyjson v0.7.7 // indirect
github.com/mattn/go-colorable v0.1.13 // indirect
@@ -113,6 +115,7 @@ require (
github.com/tidwall/match v1.1.1 // indirect
github.com/tidwall/pretty v1.2.0 // indirect
github.com/x448/float16 v0.8.4 // indirect
github.com/zeebo/xxh3 v1.0.2 // indirect
go.etcd.io/etcd/api/v3 v3.6.2 // indirect
go.etcd.io/etcd/client/pkg/v3 v3.6.2 // indirect
go.etcd.io/etcd/client/v3 v3.6.2 // indirect