Skip to content

Add ratelimit #107

@Schlaumeier5

Description

@Schlaumeier5

In SessionManager.validateSession(): increase a counter of current requests (set a maximum per minute), if it exceeds maximum, block all requests from that session.
Because normally no one asks for a session two times, you could just do Thread.sleep(2s) when you create a session (to avoid attackers creating their own session over and over again, and resetting the counter).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions