Closed Bug 697245 Opened 13 years ago Closed 11 years ago

Login should ratelimit on POST requests only

Categories

(addons.mozilla.org Graveyard :: Public Pages, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX
4.x (triaged)

People

(Reporter: cvan, Unassigned)

Details

Login page is ratelimited such that there is an allowed maximum of 15 requests per minute. This includes both GET and POST. We should be ratelimiting upon POST requests only.
Assignee: nobody → cwiemeersch
Target Milestone: --- → 6.2.9
Target Milestone: 6.2.9 → 6.3.0
Target Milestone: 6.3.0 → 6.3.2
Pushing this back since ratelimiting is still disabled.
Target Milestone: 6.3.2 → 6.3.4
Target Milestone: 6.3.4 → 6.3.3
I'll worry about this when the new login page goes live (bug 560978).
Target Milestone: 6.3.3 → 4.x (triaged)
Assignee: cvan → nobody
I don't mind GET being limited
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WONTFIX
We removed ratelimiting altogether. But ratelimiting GET was causing QA headaches.
good point
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.