Feature Request: IPv6 Throttling at /128 Granularity
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
It'll be nice if to get bruteforce protection and throttling to work at the level of individual IPv6 addresses (/128). Right now, the system seems to block larger ranges like /64 or /56, which can affect many unrelated users on the same campus or network. Even the configuration option to limit blocking to /64 (https://github.com/nextcloud/server/pull/52223) isn’t enough in this case.
How to use GitHub
- Please use the 👍 reaction to show that you are interested into the same feature.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the brute-force protection and throttling implementation, then review how IPv6 addresses are reduced to /64 or /56 ranges. Compare that behavior with the /64 configuration change referenced in pull request 52223. Done means throttling can target individual IPv6 addresses at /128 granularity without unnecessarily affecting unrelated users.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100