Close the remaining low-risk items from the full-tree review: rename the settings handler, query assigned domains in SQL, bound the login limiter map, collapse panel.js show/hide helpers, and soften DMARC copy that promised a future in-panel receiver. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -51,6 +51,8 @@ func New(st *store.Store, cfg Config, v *view.Engine, setupTokenPath string) *Mo
|
||||
loginLimiter: newRateLimiter(10, 15*time.Minute),
|
||||
trustedProxies: cfg.TrustedProxyCIDRs,
|
||||
}
|
||||
m.setupLimiter.startSweeper()
|
||||
m.loginLimiter.startSweeper()
|
||||
m.setup = newSetupManager(st, cfg.Hostname, setupTokenPath)
|
||||
return m
|
||||
}
|
||||
|
||||
@@ -44,15 +44,3 @@ func CurrentUser(r *http.Request) string {
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
// RequireGlobal wraps a handler that only global administrators may reach.
|
||||
func RequireGlobal(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
p, ok := CurrentPrincipal(r.Context())
|
||||
if !ok || !p.IsGlobal() {
|
||||
http.NotFound(w, r)
|
||||
return
|
||||
}
|
||||
next.ServeHTTP(w, r)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -5,11 +5,14 @@ import (
|
||||
"time"
|
||||
)
|
||||
|
||||
const defaultMaxBuckets = 4096
|
||||
|
||||
// rateLimiter is a simple fixed-window per-key counter used to throttle the
|
||||
// setup and login routes (security.md). Keys are client IPs.
|
||||
type rateLimiter struct {
|
||||
max int
|
||||
window time.Duration
|
||||
max int
|
||||
window time.Duration
|
||||
maxBuckets int
|
||||
|
||||
mu sync.Mutex
|
||||
buckets map[string]*rlBucket
|
||||
@@ -22,12 +25,25 @@ type rlBucket struct {
|
||||
|
||||
func newRateLimiter(max int, window time.Duration) *rateLimiter {
|
||||
return &rateLimiter{
|
||||
max: max,
|
||||
window: window,
|
||||
buckets: make(map[string]*rlBucket),
|
||||
max: max,
|
||||
window: window,
|
||||
maxBuckets: defaultMaxBuckets,
|
||||
buckets: make(map[string]*rlBucket),
|
||||
}
|
||||
}
|
||||
|
||||
func (r *rateLimiter) startSweeper() {
|
||||
go func() {
|
||||
ticker := time.NewTicker(r.window)
|
||||
defer ticker.Stop()
|
||||
for range ticker.C {
|
||||
r.mu.Lock()
|
||||
r.sweep(time.Now())
|
||||
r.mu.Unlock()
|
||||
}
|
||||
}()
|
||||
}
|
||||
|
||||
func (r *rateLimiter) Allow(key string) bool {
|
||||
now := time.Now()
|
||||
r.mu.Lock()
|
||||
@@ -35,6 +51,7 @@ func (r *rateLimiter) Allow(key string) bool {
|
||||
|
||||
b := r.buckets[key]
|
||||
if b == nil || now.After(b.windowEnds) {
|
||||
r.makeRoom(now)
|
||||
r.buckets[key] = &rlBucket{count: 1, windowEnds: now.Add(r.window)}
|
||||
r.sweep(now)
|
||||
return true
|
||||
@@ -46,6 +63,32 @@ func (r *rateLimiter) Allow(key string) bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func (r *rateLimiter) makeRoom(now time.Time) {
|
||||
if r.maxBuckets <= 0 || len(r.buckets) < r.maxBuckets {
|
||||
return
|
||||
}
|
||||
r.sweep(now)
|
||||
for len(r.buckets) >= r.maxBuckets {
|
||||
r.evictOldest()
|
||||
}
|
||||
}
|
||||
|
||||
func (r *rateLimiter) evictOldest() {
|
||||
var oldestKey string
|
||||
var oldestEnds time.Time
|
||||
first := true
|
||||
for k, b := range r.buckets {
|
||||
if first || b.windowEnds.Before(oldestEnds) {
|
||||
oldestKey = k
|
||||
oldestEnds = b.windowEnds
|
||||
first = false
|
||||
}
|
||||
}
|
||||
if oldestKey != "" {
|
||||
delete(r.buckets, oldestKey)
|
||||
}
|
||||
}
|
||||
|
||||
func (r *rateLimiter) sweep(now time.Time) {
|
||||
for k, b := range r.buckets {
|
||||
if now.After(b.windowEnds) {
|
||||
|
||||
@@ -98,3 +98,28 @@ func expire(r *rateLimiter, key string) {
|
||||
b.windowEnds = time.Now().Add(-time.Second)
|
||||
}
|
||||
}
|
||||
|
||||
// A long-running panel can see many unique client addresses. Finished buckets
|
||||
// are swept on every new window, and a hard cap evicts the oldest when the map
|
||||
// would otherwise grow without bound.
|
||||
func TestRateLimiterCapsBucketCount(t *testing.T) {
|
||||
r := newRateLimiter(1, time.Minute)
|
||||
r.maxBuckets = 3
|
||||
|
||||
for i, key := range []string{"203.0.113.7", "198.51.100.9", "192.0.2.5"} {
|
||||
if !r.Allow(key) {
|
||||
t.Fatalf("attempt %d for %s was refused under the cap", i+1, key)
|
||||
}
|
||||
expire(r, key)
|
||||
}
|
||||
|
||||
if !r.Allow("203.0.113.8") {
|
||||
t.Fatal("a fourth address was refused even though room was made")
|
||||
}
|
||||
|
||||
r.mu.Lock()
|
||||
defer r.mu.Unlock()
|
||||
if len(r.buckets) > 3 {
|
||||
t.Fatalf("bucket count = %d, want at most 3", len(r.buckets))
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user