The capture throttle guards the form and not the API, which fetches at twenty times the rate #194
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#194
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
throttle.capture--POSTULO_CAPTURE_RATE, 30 an hour per account -- is called in exactlyone place:
jobs/capture_views.py:88, the web form. The comment there says why it is tight:POST /api/v1/capturesmakes the same outbound fetch (_read()callsfetch_pagewhenno
htmlis supplied) and is bounded by nothing butPOSTULO_API_RATE: 600 an hour, pertoken. So the thing the tight limit exists for -- this server fetching addresses somebody
else chose -- is available at twenty times the rate through the API, and a token handed to
a misbehaving client is the one holder of that allowance. The form is the less capable
surface and the more limited one.
What it is not
Not a reason to put 30/h on every API capture. A capture that arrives with its HTML
fetches nothing -- that is the whole point of the browser extension sending the page it
sees -- and #177 sends forty of them from one results page in one gesture. The form counts
those too ("the parse is still work somebody asked for"), which is defensible for a form and
would cap #177 at thirty. The limit is about the fetch.
What fixing it is
Apply
throttle.capturein_read()on the branch that fetches --payload.htmlempty --and leave captures that bring their page under the API rate. Two lines and a test: a token
that asks the server to fetch a thirty-first page in an hour gets the same refusal the
form gives (
429, with the sentencethrottle.TooOftencarries), and a token that sendspages with their HTML does not.
POST /captures/previewfetches too, and should count.Worth writing where
POSTULO_CAPTURE_RATEis documented (Configuration.md) that it nowmeans fetches, on either surface.
Classification
Security, tier/2: the limit that exists to stop this server being used to fetch other
people's addresses is not applied on the surface most able to do it.