Skip to content

Comments

charts/nginz: Configure rate limits for claiming MLS key packages and getting one2one conversations#3918

Merged
smatting merged 3 commits intoq1-2024from
mls-rate-limits
Mar 5, 2024
Merged

charts/nginz: Configure rate limits for claiming MLS key packages and getting one2one conversations#3918
smatting merged 3 commits intoq1-2024from
mls-rate-limits

Conversation

@akshaymankar
Copy link
Member

https://wearezeta.atlassian.net/browse/WPB-6979

Checklist

  • Add a new entry in an appropriate subdirectory of changelog.d
  • Read and follow the PR guidelines

@zebot zebot added the ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist label Mar 4, 2024
…nd target user

When creating a conversation a client needs to get a lot of key packages, each
for a different user. If we merely just bump the limit for this endpoint, we
will allow for DoS by someone targetting a particular user. So here we rate
limit by ensuring that the target user is included in the rate limiting key.
@akshaymankar akshaymankar force-pushed the mls-rate-limits branch 3 times, most recently from 848712e to 3f33348 Compare March 5, 2024 12:11
…n/:user

During migration from proteus to MLS, this endpoint gets called for every
connection. Slowing it down just causes login to take very long.
@smatting smatting merged commit 0e275c0 into q1-2024 Mar 5, 2024
@smatting smatting deleted the mls-rate-limits branch March 5, 2024 12:26
mdimjasevic pushed a commit that referenced this pull request Apr 24, 2024
@echoes-hq echoes-hq bot added the echoes: unplanned Any work item that isn’t part of the product or technical roadmap. label Jul 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

echoes: unplanned Any work item that isn’t part of the product or technical roadmap. ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants