Rate limiting without IP tracking
- Wrong PINs are counted per case number, under an HMAC of it, so a Redis dump does not list which cases someone tried. After
MAX_ACCESS_ATTEMPTS(5) withinACCESS_LOCKOUT_MINUTES(15), the status page asks to wait. A correct PIN always works. - Admin passwords are counted per username (
MAX_LOGIN_ATTEMPTS) and across all accounts, against password spraying (ADMIN_FAILED_LOGIN_ALERT_THRESHOLD). - nginx limits every route, the submission wizard (
POST /submit) included: 10 requests/s with a burst of 30 per client address. The counters live in nginx memory only and are never logged. The onion listener has its own shared zone. - Helm: the chart sets the same limit on its ingress-nginx Ingress. With another ingress controller, set an equivalent one.