Skip to content

Consider limiting reactions as to avoid DOS/Abuse #71

@AmurgCodru

Description

@AmurgCodru

Hi

While testing reactions locally i noticed I could add tens if not hundreds of reactions and there seems to be no limit to them.

Is this the intended usage? I'd imagine a BOT spamming the DB with thousands of reactions

I was thinking of a limiter per IP (or hashed IP to avoid GDPR) to allow one of each per 24 hours.

What do you think?

I'll probably need to have a look at other systems to see how well it behaves.

Out of curiosity haven't you noticed bots trying to cling to various API's on your website?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions