admin: per-IP rate limit (5/min) on admin key attempts (#66)
This commit is contained in:
@@ -84,6 +84,12 @@ func rateLimitUnlock(id string, r *http.Request) bool {
|
||||
return globalLimiter.allow("unlock:"+id+":"+clientIP(r), 5.0/60.0, 5)
|
||||
}
|
||||
|
||||
// rateLimitAdmin: 5 attempts per minute per IP on the admin key check (#66),
|
||||
// same pattern as the unlock limiter (#34).
|
||||
func rateLimitAdmin(r *http.Request) bool {
|
||||
return globalLimiter.allow("admin:"+clientIP(r), 5.0/60.0, 5)
|
||||
}
|
||||
|
||||
// writeRateLimited responds 429 with Retry-After based on refill rate.
|
||||
func writeRateLimited(w http.ResponseWriter, retryAfterSecs int) {
|
||||
w.Header().Set("Retry-After", strconv.Itoa(retryAfterSecs))
|
||||
|
||||
Reference in New Issue
Block a user