瀏覽代碼

allow localhost to bypass the ratelimit (#2554)

master
Tristan Mahé 7 年之前
committed by Eugen Rochko
父節點
當前提交
964035b118
共有 1 個文件被更改,包括 7 次插入0 次删除
  1. +7
    -0
      config/initializers/rack_attack.rb

+ 7
- 0
config/initializers/rack_attack.rb 查看文件

@@ -1,6 +1,13 @@
# frozen_string_literal: true

class Rack::Attack
# Always allow requests from localhost
# (blocklist & throttles are skipped)
Rack::Attack.safelist('allow from localhost') do |req|
# Requests are allowed if the return value is truthy
'127.0.0.1' == req.ip || '::1' == req.ip
end

# Rate limits for the API
throttle('api', limit: 300, period: 5.minutes) do |req|
req.ip if req.path =~ /\A\/api\/v/


Loading…
取消
儲存