aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md5
1 files changed, 5 insertions, 0 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 6d7b355..577ab82 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -132,6 +132,11 @@ internal/web/ server.go (host router, middleware, render helpers)
limits for the Files page's multi-upload (`maxUploadFiles` = 10). Errors
from `guardPOST` go through `s.fail`, which answers JSON when the request
has `Accept: application/json` (the upload scripts).
+- **Hardening** (`web/ratelimit.go`): a per-key token bucket throttles the
+ anonymous endpoints worth abusing — `loginLimit` on `POST /webadmin`, keyed
+ by client address *and* by lowercased username (10 at once, then 10 a
+ minute each), answered with 429 by `s.throttle` and a log line. Flood
+ control for everything else stays at the reverse proxy (`limit_req`).
- **Templates**: each page file is parsed together with its layout
(`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all
`partials/*.html`. Page files define `content` (and optionally `title`).