0xMiden / 0xMiden/note-transport-service
No rate limiting or per-client request quotas
- Langage dominant
- Rust
- Étoiles
- 3
- Forks
- 10
- Merge moyen
- 2 h 23 min
- PR mergées (30 j)
- 4
Description
Severity: critical (for an internet-facing deployment).
### Summary
There is no per-IP, per-client, or per-RPC rate limiting. The only throttle is a global 4096 in-flight-request limit (`GlobalConcurrencyLimitLayer::new`, `crates/node/src/node/grpc/mod.rs:121`). Remote peer address is never inspected. A single client can saturate the write, read, and stream paths at line rate.
This is the concrete mechanism behind placeholder #44 (spam protection).
### Recommendation
- Add per-IP rate limiting (tower middleware, or document a mandatory upstream proxy/WAF) with separate budgets for writes (`SendNote`) vs reads (`FetchNotes`/`StreamNotes`).
- Add a global write-rate cap.
- Reject with `RESOURCE_EXHAUSTED` rather than queueing (see the concurrency/timeout-ordering note in the papercuts issue).
Related: #44, and the auth-model issue (rate limits are only meaningful once "who is a client" is defined).
---
Part of #114.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.