Add honeypot field and per-IP rate limit to registration #11
Loading…
Reference in a new issue
No description provided.
Delete branch "cc-4-spam"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds a hidden
websitehoneypot to the register form and an in-memory limit of 5 submits per 60 seconds per client IP (firstX-Forwarded-Forentry, else the socket address). A filled honeypot gets the normal 303 to/thankswith nothing logged. Over the limit gets a 429, andsite.jsshows "Too many tries, give it a minute."Needs NPM to pass
X-Forwarded-For(noted in README). The limit is per process and resets on restart.Tested:
node --test(15 pass),html-validateclean. Axe not run here.Ticket: CC-4
test/server.test.js: the other register tests post with no X-Forwarded-For, so they share one limiter key. They already use 4 of the 5 slots. The next register test added there will get a 429. Give the shared
posthelper a unique X-Forwarded-For per call, or leave a slot free.