mirror of
https://github.com/discourse/discourse.git
synced 2026-08-04 10:39:43 +08:00
Load balancers health check every backend they route to, and every backend increments the same Redis-backed per-IP counter, so health check volume scales linearly with backend count while the per-IP budget does not. With enough backends, health checks alone exceed the limit and every backend gets marked down with 429s. Key /srv/status requests on source IP plus backend hostname via a new HealthCheck rate limiter ahead of the IP limiter. Each backend gets its own budget, so the per-key rate stays constant regardless of scale, and health checks remain rate limited. Health checks from private address space skip rate limiting by default, so most deployments see no behavior change. This matters when load balancers check from publicly-routable addresses, such as public IPv6 ranges. An attacker gains N x rate_limit on /srv/status across N backends, which is not a practical concern for one of the cheapest routes in the application. |
||
|---|---|---|
| .. | ||
| anonymous_cache.rb | ||
| crawler_hooks.rb | ||
| csp_script_nonce_injector.rb | ||
| default_headers.rb | ||
| discourse_public_exceptions.rb | ||
| enforce_hostname.rb | ||
| missing_avatars.rb | ||
| omniauth_bypass_middleware.rb | ||
| overload_protections.rb | ||
| processing_request.rb | ||
| request_tracker.rb | ||
| track_view_session_id_injector.rb | ||