Expand description
Abuse controls for the public audit (spec section 8): who is asking (the client address and
its daily-salted hash) and which email domains are throwaways. The limits themselves live in
the store, next to the data they count; Turnstile is in crate::turnstile.
Structs§
- Client
Ip - The visitor’s address as far as limits are concerned.
Noneonly when it can’t be told (no proxy header and no socket address, which doesn’t happen when serving), in which case the per-IP limits don’t apply.
Functions§
- client_
ip - In the cloud, the address the proxy in front of us reports (
CLIENT_IP_HEADER, by defaultCF-Connecting-IP); everywhere else, and when that header is missing or isn’t an address, the socket’s peer. Self-hosted instances never trust a client-supplied header. - ip_hash
- What is stored on a crawl instead of the visitor’s address: SHA-256 over a salt that changes every UTC day (derived from the instance secret), then the address. Yesterday’s hashes can’t be matched to today’s, so the counters can’t build a history of a person. IPv6 addresses count by their /64, since a person controls every address in it.
- is_
disposable - wait_
text about 59 minutes,about 22 hours: how long until a limit lifts.