Commit b34f7ec
committed
ops(nginx): extend register rate limit to /bots/bootstrap + /bots/import-source
Defense-in-depth on remaining entity-creating endpoints after the
attacker pivoted from /auth/register to /agents/register. Backend
has app-layer limits (5/hr per IP on bootstrap) but nginx layer
keeps probes from reaching backend.1 parent 88ae7b3 commit b34f7ec
1 file changed
Lines changed: 20 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
227 | 227 | | |
228 | 228 | | |
229 | 229 | | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
230 | 250 | | |
231 | 251 | | |
232 | 252 | | |
| |||
0 commit comments