gitlab-org--gitlab-foss/config/initializers/rack_attack_global.rb

62 lines
1.9 KiB
Ruby
Raw Normal View History

2017-10-17 12:40:09 -04:00
module Gitlab::Throttle
2017-09-15 13:31:32 -04:00
def self.settings
Gitlab::CurrentSettings.current_application_settings
end
2017-10-17 12:40:09 -04:00
def self.unauthenticated_options
2017-09-15 13:31:32 -04:00
limit_proc = proc { |req| settings.throttle_unauthenticated_requests_per_period }
period_proc = proc { |req| settings.throttle_unauthenticated_period_in_seconds.seconds }
{ limit: limit_proc, period: period_proc }
end
2017-10-17 12:40:09 -04:00
def self.authenticated_api_options
2017-09-15 13:31:32 -04:00
limit_proc = proc { |req| settings.throttle_authenticated_api_requests_per_period }
period_proc = proc { |req| settings.throttle_authenticated_api_period_in_seconds.seconds }
{ limit: limit_proc, period: period_proc }
end
2017-10-17 12:40:09 -04:00
def self.authenticated_web_options
2017-09-15 13:31:32 -04:00
limit_proc = proc { |req| settings.throttle_authenticated_web_requests_per_period }
period_proc = proc { |req| settings.throttle_authenticated_web_period_in_seconds.seconds }
{ limit: limit_proc, period: period_proc }
end
2017-10-17 12:40:09 -04:00
end
2017-09-15 13:31:32 -04:00
2017-10-17 12:40:09 -04:00
class Rack::Attack
throttle('throttle_unauthenticated', Gitlab::Throttle.unauthenticated_options) do |req|
Gitlab::Throttle.settings.throttle_unauthenticated_enabled &&
req.unauthenticated? &&
req.ip
end
2017-09-15 13:31:32 -04:00
2017-10-17 12:40:09 -04:00
throttle('throttle_authenticated_api', Gitlab::Throttle.authenticated_api_options) do |req|
Gitlab::Throttle.settings.throttle_authenticated_api_enabled &&
req.api_request? &&
req.authenticated_user_id
2017-09-15 13:31:32 -04:00
end
2017-10-17 12:40:09 -04:00
throttle('throttle_authenticated_web', Gitlab::Throttle.authenticated_web_options) do |req|
Gitlab::Throttle.settings.throttle_authenticated_web_enabled &&
req.web_request? &&
req.authenticated_user_id
end
2017-09-15 13:31:32 -04:00
class Request
def unauthenticated?
!authenticated_user_id
end
def authenticated_user_id
2017-10-13 20:05:18 -04:00
Gitlab::Auth::RequestAuthenticator.new(self).user&.id
2017-09-15 13:31:32 -04:00
end
def api_request?
path.start_with?('/api')
end
def web_request?
!api_request?
end
end
end