0
0
Fork 0
mirror of https://github.com/nextcloud/server.git synced 2025-05-19 20:52:07 +00:00
nextcloud_server/lib/private/Security/RateLimiting/Limiter.php
Daniel Kesselberg a53e15c971
fix: log requests exceeding the rate limiting
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de>
2025-05-14 12:23:40 +02:00

81 lines
2.1 KiB
PHP

<?php
declare(strict_types=1);
/**
* SPDX-FileCopyrightText: 2017 Nextcloud GmbH and Nextcloud contributors
* SPDX-License-Identifier: AGPL-3.0-or-later
*/
namespace OC\Security\RateLimiting;
use OC\Security\Normalizer\IpAddress;
use OC\Security\RateLimiting\Backend\IBackend;
use OC\Security\RateLimiting\Exception\RateLimitExceededException;
use OCP\IUser;
use OCP\Security\RateLimiting\ILimiter;
use Psr\Log\LoggerInterface;
class Limiter implements ILimiter {
public function __construct(
private IBackend $backend,
private LoggerInterface $logger,
) {
}
/**
* @param int $period in seconds
* @throws RateLimitExceededException
*/
private function register(
string $methodIdentifier,
string $userIdentifier,
int $period,
int $limit,
): void {
$existingAttempts = $this->backend->getAttempts($methodIdentifier, $userIdentifier);
if ($existingAttempts >= $limit) {
$this->logger->info('Request blocked because it exceeds the rate limit [method: {method}, limit: {limit}, period: {period}]', [
'method' => $methodIdentifier,
'limit' => $limit,
'period' => $period,
]);
throw new RateLimitExceededException();
}
$this->backend->registerAttempt($methodIdentifier, $userIdentifier, $period);
}
/**
* Registers attempt for an anonymous request
*
* @param int $anonPeriod in seconds
* @throws RateLimitExceededException
*/
public function registerAnonRequest(
string $identifier,
int $anonLimit,
int $anonPeriod,
string $ip,
): void {
$ipSubnet = (new IpAddress($ip))->getSubnet();
$anonHashIdentifier = hash('sha512', 'anon::' . $identifier . $ipSubnet);
$this->register($identifier, $anonHashIdentifier, $anonPeriod, $anonLimit);
}
/**
* Registers attempt for an authenticated request
*
* @param int $userPeriod in seconds
* @throws RateLimitExceededException
*/
public function registerUserRequest(
string $identifier,
int $userLimit,
int $userPeriod,
IUser $user,
): void {
$userHashIdentifier = hash('sha512', 'user::' . $identifier . $user->getUID());
$this->register($identifier, $userHashIdentifier, $userPeriod, $userLimit);
}
}