From: Eugen Rochko Date: Sun, 7 Apr 2019 02:26:43 +0000 (+0200) Subject: Add rate limit for media proxy requests (#10490) X-Git-Url: https://git.xn--scling-oua.cat.family/?a=commitdiff_plain;h=0e8819f0e8729cda54231ed7a76dd10eb2083bdf;p=mastodon.git Add rate limit for media proxy requests (#10490) 30 per 30 minutes, like media uploads --- diff --git a/config/initializers/rack_attack.rb b/config/initializers/rack_attack.rb index 28201cc64..ae3eede66 100644 --- a/config/initializers/rack_attack.rb +++ b/config/initializers/rack_attack.rb @@ -57,6 +57,10 @@ class Rack::Attack req.authenticated_user_id if req.post? && req.path.start_with?('/api/v1/media') end + throttle('throttle_media_proxy', limit: 30, period: 30.minutes) do |req| + req.ip if req.path.start_with?('/media_proxy') + end + throttle('throttle_api_sign_up', limit: 5, period: 30.minutes) do |req| req.ip if req.post? && req.path == '/api/v1/accounts' end