Skip to main content

Module abuse

Module abuse 

Source
Expand description

Abuse controls for the public audit (spec section 8): who is asking (the client address and its daily-salted hash) and which email domains are throwaways. The limits themselves live in the store, next to the data they count; Turnstile is in crate::turnstile.

Structs§

ClientIp
The visitor’s address as far as limits are concerned. None only when it can’t be told (no proxy header and no socket address, which doesn’t happen when serving), in which case the per-IP limits don’t apply.

Functions§

client_ip
In the cloud, the address the proxy in front of us reports (CLIENT_IP_HEADER, by default CF-Connecting-IP); everywhere else, and when that header is missing or isn’t an address, the socket’s peer. Self-hosted instances never trust a client-supplied header.
ip_hash
What is stored on a crawl instead of the visitor’s address: SHA-256 over a salt that changes every UTC day (derived from the instance secret), then the address. Yesterday’s hashes can’t be matched to today’s, so the counters can’t build a history of a person. IPv6 addresses count by their /64, since a person controls every address in it.
is_disposable
wait_text
about 59 minutes, about 22 hours: how long until a limit lifts.