SPEC follows milestones 1 and 2: build order, two size limits, GeoJS answers in memory (closes #16)
The build order starts with milestone 1 and milestone 2, then keeps the earlier stages in their order, less what the two milestones build. Milestone 2 builds the container image with runit and the health check, so it answers /_smallwebwaf/healthz before the other admin endpoints. The four body-size settings become SWWAF_REQUEST_MAX_BYTES and SWWAF_RESPONSE_MAX_BYTES, since bodies pass through unchanged; the four timeouts stay. GeoJS answers are kept in memory; lookups.json comes in milestone 3 or later, as sneak ruled. README.md: the two sentences this change made wrong. Model: opus-5-5
This commit is contained in:
@@ -56,9 +56,10 @@ goes through the candidates one by one.
|
||||
- Real client address worked out from `X-Forwarded-For`, trusting only the proxy
|
||||
networks you list, by default the private address ranges. IPv6 clients are
|
||||
counted by /64 by default.
|
||||
- Size and time limits on requests and responses, both between the client and
|
||||
`smallwebwaf` and between `smallwebwaf` and the app: by default a request may
|
||||
take 60 seconds and 100 MiB, a response 30 minutes and 5 GiB.
|
||||
- Size and time limits on requests and responses, with the time limits both
|
||||
between the client and `smallwebwaf` and between `smallwebwaf` and the app: by
|
||||
default a request may take 60 seconds and 100 MiB, a response 30 minutes and 5
|
||||
GiB.
|
||||
- Rate limits per client on requests per minute, per hour and per day, and on
|
||||
bytes per minute, per hour and per day, on by default and set well above what
|
||||
real visitors need.
|
||||
@@ -212,10 +213,11 @@ request log, the metrics and the ban notes, and for the country lists and biased
|
||||
limits when you set them. It works with no setup: by default it asks the free
|
||||
GeoJS web service, which needs no account and no file. This means that, by
|
||||
default, the address of every new visitor is sent to GeoJS. Each answer is kept
|
||||
for seven days, across restarts, and many addresses are asked about in one
|
||||
request. GeoJS publishes no rate limit but may block a caller it thinks asks too
|
||||
much; while it is not answering, new visitors count as coming from an unknown
|
||||
country, which `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses.
|
||||
in memory for seven days, and many addresses are asked about in one request;
|
||||
writing the answers to disk, so that they survive a restart, comes in milestone
|
||||
3 or later. GeoJS publishes no rate limit but may block a caller it thinks asks
|
||||
too much; while it is not answering, new visitors count as coming from an
|
||||
unknown country, which `SWWAF_EXCLUSIVELY_ALLOWED_COUNTRIES` refuses.
|
||||
|
||||
To keep your visitors' addresses on your own host, set
|
||||
`SWWAF_LOOKUP_SOURCE=off`, or use the database file instead of GeoJS:
|
||||
|
||||
Reference in New Issue
Block a user