221c1f31b0
Backend (each change benchmark-gated with BEFORE replicas + equivalence gates; see examples/bench_round11_micro.rs, bench_round11_queries.rs, bench_log_writer.rs and benches/ROUND11.md — final numbers land in the follow-up doc commit): - StoragePath re-representation: single canonical joined String, segments derived on demand; File/Folder drop the duplicated path_string field (4000→1000 allocs per 500-row listing page) - Display classifier fusion: classify_display shares one stack-lowered extension across the three decision trees; call sites in FileDto, folder/favorites/recent handlers, trash, path-resolver (+ interning where Arc::from was still used) - /status.php and /openapi.json memoized into OnceLock<Bytes> (openapi rebuilt a 171 KiB spec per request: 2.8 ms → 18 ns) - NC upload-session PROPFIND: write! + pre-sized body + stack RFC2822 dates (2.3-2.6x, 2582→772 allocs at 256 chunks) - REST download: dead FileDto clone removed (capture mime/size + move) - CalendarEventDto/TrashedItem into_parts moves (11 KiB ical_data memcpy gone per CalDAV row); CardDAV getlastmodified stack render - 4xx path: borrowed ErrorResponse serialize, ErrorKind::as_str, not_found/already_exists clone kill - vCard emit via write!; search page moved out with into_iter skip/take; content-hit UUIDs parsed once; group last-user check via HashSet - RateLimiter: lock-free get + insert (and_upsert_with variant REJECTED by benchmark); CSRF token borrow-compare + borrowed cookie extraction - Thumbnail/preview ETags built from as_str (Debug-identical bytes) - Encrypted backend: encrypt_in_place_detached single-buffer write path, chunk-sized reserve in collect_stream; retry labels made lazy - PG: deferred upload registration 3→1 round-trips (persist_file CTE template); direct_grant_cache for Calendar/AddressBook/Playlist authz (single-flight + set_role/clear_role invalidation); expand_user tokio::join!; geo clusters min(uuid)::text; recluster face assignment batched into one UNNEST update - People recluster cosine: norms precomputed once (bit-identical gate) - NC capabilities poll logs demoted to debug; tracing-appender dep added for the log-writer benchmark Frontend: - ResourceList.selectedEntries O(N)-per-toggle → id-index projection O(k log k); favorites/recent consume the batchToolbar snippet param and drop their duplicate filter + dead selectedIds mirror - Recent: star state via new favoriteIds prop — a star click no longer rebuilds all N entries - admin timeAgo >30d fallback uses the cached Intl.DateTimeFormat - vitest gates in src/lib/components/round11.bench.test.ts Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ABhTEHuGujvwoodh67Kga7
176 lines
6.1 KiB
Rust
176 lines
6.1 KiB
Rust
//! IP-based rate limiting middleware for authentication endpoints.
|
|
//!
|
|
//! Uses `moka` TTL caches (already a project dependency) to track request
|
|
//! counts per client IP. Each protected endpoint group gets its own
|
|
//! [`RateLimiter`] instance with independently tuneable limits.
|
|
//!
|
|
//! Client IP resolution is delegated to [`super::trusted_proxy::client_ip`],
|
|
//! which honours `OXICLOUD_TRUST_PROXY_CIDR` for proxy-header forwarding.
|
|
//!
|
|
//! When the limit is exceeded a `429 Too Many Requests` response is returned
|
|
//! with a `Retry-After` header indicating how many seconds to wait.
|
|
|
|
use axum::{
|
|
http::{HeaderValue, Request, StatusCode},
|
|
middleware::Next,
|
|
response::{IntoResponse, Response},
|
|
};
|
|
use moka::sync::Cache;
|
|
use std::sync::Arc;
|
|
use std::time::Duration;
|
|
|
|
/// A simple sliding-window counter keyed by IP address.
|
|
///
|
|
/// Each key lives for `window` seconds; every request increments the counter.
|
|
/// Once the counter reaches `max_requests` the request is rejected.
|
|
#[derive(Clone)]
|
|
pub struct RateLimiter {
|
|
/// Maps `IP -> request_count` with automatic TTL expiration.
|
|
cache: Cache<String, u32>,
|
|
/// Maximum requests allowed within the window.
|
|
max_requests: u32,
|
|
/// Window duration in seconds (also used for `Retry-After`).
|
|
window_secs: u64,
|
|
}
|
|
|
|
impl RateLimiter {
|
|
/// Create a new rate limiter.
|
|
///
|
|
/// * `max_requests`, ceiling per IP within the window
|
|
/// * `window_secs` , sliding window duration
|
|
/// * `max_entries` , upper bound on tracked IPs (evicts LRU when exceeded)
|
|
pub fn new(max_requests: u32, window_secs: u64, max_entries: u64) -> Self {
|
|
let cache = Cache::builder()
|
|
.time_to_live(Duration::from_secs(window_secs))
|
|
.max_capacity(max_entries)
|
|
.build();
|
|
Self {
|
|
cache,
|
|
max_requests,
|
|
window_secs,
|
|
}
|
|
}
|
|
|
|
/// Check whether the IP is allowed. Returns `Ok(current_count)` or
|
|
/// `Err(StatusCode::TOO_MANY_REQUESTS)`.
|
|
#[allow(clippy::result_unit_err)]
|
|
pub fn check_and_increment(&self, ip: &str) -> Result<u32, ()> {
|
|
// Lock-free read (borrows the key — no allocation), then one
|
|
// write-back. The previous shape allocated the key TWICE and paid
|
|
// a locking `entry()` op on top of the insert; moka's
|
|
// `and_upsert_with` alternative benchmarked slower still
|
|
// (benches/ROUND11.md §20). Read-then-write is not atomic, but it
|
|
// never was — under a concurrent burst both shapes can undercount
|
|
// the same way, which only makes the limiter marginally lenient,
|
|
// never wrongly strict.
|
|
let count = self.cache.get(ip).unwrap_or(0) + 1;
|
|
|
|
// On re-insert moka resets the TTL; for rate limiting this is fine
|
|
// because it means the window "slides" forward on activity.
|
|
self.cache.insert(ip.to_string(), count);
|
|
|
|
if count > self.max_requests {
|
|
Err(())
|
|
} else {
|
|
Ok(count)
|
|
}
|
|
}
|
|
|
|
/// Seconds the client should wait before retrying.
|
|
pub fn retry_after(&self) -> u64 {
|
|
self.window_secs
|
|
}
|
|
}
|
|
|
|
// ─── Axum middleware factories ──────────────────────────────────────────────
|
|
|
|
/// Extract the most-likely real client IP from headers / connection info.
|
|
///
|
|
/// Proxy headers (`X-Forwarded-For`, `X-Real-Ip`) are only trusted when the
|
|
/// TCP peer address falls within `OXICLOUD_TRUST_PROXY_CIDR`. Without a
|
|
/// configured CIDR list an attacker could spoof headers to bypass rate limiting.
|
|
pub fn extract_client_ip<B>(req: &Request<B>) -> String {
|
|
super::trusted_proxy::client_ip(req, false)
|
|
}
|
|
|
|
/// Build a rate-limit response with the standard `Retry-After` header.
|
|
///
|
|
/// Public so handlers that do their own (non-middleware) rate checks —
|
|
/// e.g. the email-invite branch of `POST /api/grants`, where the limit
|
|
/// only applies to one subject variant — can return the same shape.
|
|
pub fn too_many_requests(retry_after: u64) -> Response {
|
|
let body = serde_json::json!({
|
|
"error": "Too many requests",
|
|
"retry_after_secs": retry_after,
|
|
});
|
|
let mut resp = (StatusCode::TOO_MANY_REQUESTS, axum::Json(body)).into_response();
|
|
if let Ok(val) = HeaderValue::from_str(&retry_after.to_string()) {
|
|
resp.headers_mut().insert("retry-after", val);
|
|
}
|
|
resp
|
|
}
|
|
|
|
/// Axum middleware: rate-limit login attempts.
|
|
///
|
|
/// Inject via:
|
|
/// ```ignore
|
|
/// .layer(axum::middleware::from_fn_with_state(limiter, rate_limit_login))
|
|
/// ```
|
|
pub async fn rate_limit_login(
|
|
State(limiter): axum::extract::State<Arc<RateLimiter>>,
|
|
req: Request<axum::body::Body>,
|
|
next: Next,
|
|
) -> Response {
|
|
let ip = extract_client_ip(&req);
|
|
match limiter.check_and_increment(&ip) {
|
|
Ok(_) => next.run(req).await,
|
|
Err(()) => {
|
|
tracing::warn!(
|
|
ip = %ip,
|
|
"Rate limit exceeded on login endpoint"
|
|
);
|
|
too_many_requests(limiter.retry_after())
|
|
}
|
|
}
|
|
}
|
|
|
|
/// Axum middleware: rate-limit registration attempts.
|
|
pub async fn rate_limit_register(
|
|
State(limiter): axum::extract::State<Arc<RateLimiter>>,
|
|
req: Request<axum::body::Body>,
|
|
next: Next,
|
|
) -> Response {
|
|
let ip = extract_client_ip(&req);
|
|
match limiter.check_and_increment(&ip) {
|
|
Ok(_) => next.run(req).await,
|
|
Err(()) => {
|
|
tracing::warn!(
|
|
ip = %ip,
|
|
"Rate limit exceeded on register endpoint"
|
|
);
|
|
too_many_requests(limiter.retry_after())
|
|
}
|
|
}
|
|
}
|
|
|
|
/// Axum middleware: rate-limit token refresh attempts.
|
|
pub async fn rate_limit_refresh(
|
|
State(limiter): axum::extract::State<Arc<RateLimiter>>,
|
|
req: Request<axum::body::Body>,
|
|
next: Next,
|
|
) -> Response {
|
|
let ip = extract_client_ip(&req);
|
|
match limiter.check_and_increment(&ip) {
|
|
Ok(_) => next.run(req).await,
|
|
Err(()) => {
|
|
tracing::warn!(
|
|
ip = %ip,
|
|
"Rate limit exceeded on refresh endpoint"
|
|
);
|
|
too_many_requests(limiter.retry_after())
|
|
}
|
|
}
|
|
}
|
|
|
|
use axum::extract::State;
|