0xMiden / 0xMiden/note-transport-service

No rate limiting or per-client request quotas

Đang mở
#117 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
enhancement production-readiness
Ngôn ngữ chính
Rust
Star
3
Fork
10
Merge trung bình
2 giờ 23 phút
Pull request đã merge (30 ngày)
4

Mô tả

Severity: critical (for an internet-facing deployment).

### Summary

There is no per-IP, per-client, or per-RPC rate limiting. The only throttle is a global 4096 in-flight-request limit (`GlobalConcurrencyLimitLayer::new`, `crates/node/src/node/grpc/mod.rs:121`). Remote peer address is never inspected. A single client can saturate the write, read, and stream paths at line rate.

This is the concrete mechanism behind placeholder #44 (spam protection).

### Recommendation

- Add per-IP rate limiting (tower middleware, or document a mandatory upstream proxy/WAF) with separate budgets for writes (`SendNote`) vs reads (`FetchNotes`/`StreamNotes`).
- Add a global write-rate cap.
- Reject with `RESOURCE_EXHAUSTED` rather than queueing (see the concurrency/timeout-ordering note in the papercuts issue).

Related: #44, and the auth-model issue (rate limits are only meaningful once "who is a client" is defined).

---
Part of #114.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.