Byte limits per client over a minute, an hour and a day (closes #20)
check / check (push) Canceled after 0s

SWWAF_BYTES_LIMIT_PER_MINUTE, _PER_HOUR and _PER_DAY (10G, 20G, 50G)
and SWWAF_BYTES_COUNT (both). A request's bytes are counted once its
answer has ended, for a request passed to the app that the rate limits
count. Bytes over a limit ban the client as a broken rate limit does,
without cutting the answer short. clients.json keeps the byte buckets,
the log line's counts carry the byte totals, ban notes say what the
limit is on, and the limit hits metric is labelled by kind.

Judgement call: limit_hit names a byte window minute_bytes, hour_bytes
or day_bytes, as counts names the byte totals.
Judgement call: in observe mode, the bytes of a request enforce mode
would have refused are not counted.

Model: opus-5-5
This commit is contained in:
2026-10-07 09:23:42 +00:00
parent 0dc26041dc
commit 401c57a52a
22 changed files with 1119 additions and 299 deletions
+1
View File
@@ -284,6 +284,7 @@ func TestBanNotes(t *testing.T) {
ASN: asnDE,
ASName: asNameDE,
Country: "DE",
Kind: "requests",
Limit: 1,
Window: minute,
Count: 2,