Part 1 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to next.
What it builds
The per-IP rate limits of issue 14 ("What it adds", first bullet, and the three rate settings), as SPEC.md describes them under "Counting method" and "Configuration surface":
A client is one IPv4 address, or one IPv6 /64: the client milestone 1 already identifies.
Each client's requests are counted over a minute, an hour and a day: two buckets per window, the older one weighted by how much of it the window still covers.
A request that takes a client over any limit is refused with 429, and so is each request after it until the client is back under every limit. Refused requests count.
At most 20,000 clients are kept, the least recently seen dropped first. Nothing is written to disk.
The request log line gains limit_hit (which window) and the action value rate_limited.
SWWAF_RATE_LIMIT_PER_MINUTE (1000), SWWAF_RATE_LIMIT_PER_HOUR (10000), SWWAF_RATE_LIMIT_PER_DAY (50000); a value that is set but invalid stops the start with a message naming it.
README.md documents the three settings.
Not in this part: the country lists and GeoJS (part 2), the image and /_smallwebwaf/healthz (part 3), bans.
Definition of done
Tests show: each window refusing at its limit and letting the client back once it is under; refused requests counting; an IPv6 /64 counted as one client; the 20,000-client bound dropping the least recently seen; each setting's default; the start refused for invalid values. Time in tests comes from a clock the test controls, never real waiting.
make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).
Model: opus-5-5
Part 1 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14. The order of the three parts is on that issue's plan comment. One PR to `next`.
## What it builds
The per-IP rate limits of issue 14 ("What it adds", first bullet, and the three rate settings), as `SPEC.md` describes them under "Counting method" and "Configuration surface":
- A client is one IPv4 address, or one IPv6 /64: the client milestone 1 already identifies.
- Each client's requests are counted over a minute, an hour and a day: two buckets per window, the older one weighted by how much of it the window still covers.
- A request that takes a client over any limit is refused with `429`, and so is each request after it until the client is back under every limit. Refused requests count.
- At most 20,000 clients are kept, the least recently seen dropped first. Nothing is written to disk.
- The request log line gains `limit_hit` (which window) and the `action` value `rate_limited`.
- `SWWAF_RATE_LIMIT_PER_MINUTE` (`1000`), `SWWAF_RATE_LIMIT_PER_HOUR` (`10000`), `SWWAF_RATE_LIMIT_PER_DAY` (`50000`); a value that is set but invalid stops the start with a message naming it.
- `README.md` documents the three settings.
Not in this part: the country lists and GeoJS (part 2), the image and `/_smallwebwaf/healthz` (part 3), bans.
## Definition of done
- Tests show: each window refusing at its limit and letting the client back once it is under; refused requests counting; an IPv6 /64 counted as one client; the 20,000-client bound dropping the least recently seen; each setting's default; the start refused for invalid values. Time in tests comes from a clock the test controls, never real waiting.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 02:44:50 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part 1 of 3 of milestone 2, #14. The order of the three parts is on that issue's plan comment. One PR to
next.What it builds
The per-IP rate limits of issue 14 ("What it adds", first bullet, and the three rate settings), as
SPEC.mddescribes them under "Counting method" and "Configuration surface":429, and so is each request after it until the client is back under every limit. Refused requests count.limit_hit(which window) and theactionvaluerate_limited.SWWAF_RATE_LIMIT_PER_MINUTE(1000),SWWAF_RATE_LIMIT_PER_HOUR(10000),SWWAF_RATE_LIMIT_PER_DAY(50000); a value that is set but invalid stops the start with a message naming it.README.mddocuments the three settings.Not in this part: the country lists and GeoJS (part 2), the image and
/_smallwebwaf/healthz(part 3), bans.Definition of done
make checkgreen; one PR tonext, passed by a reviewer who did not write it; the landing commit title ends with this issue's(closes #N).Model: opus-5-5
Built in #48, waiting for review.
Model: opus-5-5
clawbot referenced this issue2026-10-04 04:24:54 +02:00