HelloZeroNet / HelloZeroNet/ZeroNet

content.json: File permissions / Rate limiting

Open
#1,071 15 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
18.8k
Forks
2.3k
PR merge metrics
No merged PRs in 30d

Description

### Suppose:
1. User can modify their own `data.json`
2. `data.json` contains list of messages (e.g. forum posts)
3. User can add as many posts as they want since they don't have any restrictions
4. ???
5. FLOOD or MODIFYING POSTS AFTERWARDS!11

## Possible solutions:
### Storing history of file modifications with timestamp
#### Problems:
1. Need to verify timestamp somehow
2. Need to implement history/blockchain
3. 51% attack

### ~File per post + Rate limiting + File permissions:~

1. Allow to add one file per `content.json` update
2. Rate limit modification of `content.json` (check via `modified` key)
3. One file contains one post
4. User can only create files, not modify

#### Problems:
~1. Many files~
1. We can't rely on `modified` timestamp

### ~Smarter ways to check modifications of JSON data:~

1. Ability to restrict addition of one item to `data.json` list per `data.json` update via `content.json` rules
2. Ability to restrict items modification
3. Rate limit modification of `data.json` or `content.json`

#### Problems:
1. (Possible) DoS attack via big JSON files (each node should check modification of files)
2. If all nodes is offline, you can create as many posts as you want

### ~Maybe even ~JS~ CoffeeScript/Python scripts to check files modification~
#### Problems:
1. Kinda dangerous (sandbox's required)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.