Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
808245e7d5 |
@@ -109,13 +109,12 @@ bytes). Rate limits are whole numbers of requests. Netblocks are in CIDR form,
|
||||
and a bare address stands for itself alone. `off` switches a timeout, a size
|
||||
limit or a rate limit off.
|
||||
|
||||
Four limits are fixed rather than settings. The request line and headers may
|
||||
take up to 32 KiB, above which the answer is `431` and nothing reaches the app.
|
||||
A kept-open connection that sends nothing for 120 seconds is closed. That is
|
||||
Two limits are fixed rather than settings: the request line and headers may take
|
||||
up to 32 KiB, above which the answer is `431` and nothing reaches the app, and a
|
||||
kept-open connection that sends nothing for 120 seconds is closed. That is
|
||||
longer than the 90 seconds after which traefik closes a connection it is not
|
||||
using, so traefik never sends a request on a connection `smallwebwaf` is
|
||||
closing. At most 20,000 clients are kept for the rate limits, and an IPv6 client
|
||||
is counted by its /64.
|
||||
closing.
|
||||
|
||||
## Request log
|
||||
|
||||
|
||||
@@ -54,25 +54,6 @@ func TestEachWindowRefusesAtItsLimitAndLetsTheClientBack(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientBackAfterAWholeBucketIsWithinTheLimitAtOnce(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
limiter := ratelimit.New(ratelimit.Limits{PerHour: limit})
|
||||
client := netip.MustParsePrefix("203.0.113.9/32")
|
||||
start := midnight()
|
||||
|
||||
for range limit {
|
||||
wantCount(t, limiter, client, start, "")
|
||||
}
|
||||
|
||||
wantCount(t, limiter, client, start, hour)
|
||||
|
||||
// No request in the whole next bucket, so a quarter into the one after
|
||||
// it the window covers none of the four requests: 1 is within the
|
||||
// limit. Were they counted as the bucket before, 3 + 1 would be over.
|
||||
wantCount(t, limiter, client, start.Add(2*time.Hour+time.Hour/4), "")
|
||||
}
|
||||
|
||||
func TestRefusedRequestsCount(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user