4 ms·
Could you please explain how sending a 404 to clients sending too many requests would adhere to the HTTP standards? I’m not against the blocking itself. For re
by pgraf 3y ago
Could you please explain how sending a 404 to clients sending too many requests would adhere to the HTTP standards? I’m not against the blocking itself.
For reference:
https://datatracker.ietf.org/doc/html/rfc7231#section-6.5.4 https://datatracker.ietf.org/doc/html/rfc7231#section-6.5.4
- Alifatisk 3y agoWhen I say you can still adhere to the HTTP standards, I mean that you just have to adjust the suggested settings in the config, so requests reaching over the throttle should give 429 instead of 404: Like the following: # config/routes.rb get "429", to: "welcome#429", code: 429 rescue_from ActiveRecord::RecordNotFound, with: :too_many_requests def too_many_requests redirect_to "/warning" end # config/initializers/rack-attack.rb class Rack::Attack ... blocklist("block 429") do |request| Allow2Ban.filter("too_many_requests-#{request.ip}", maxretry: 5, findtime: 3.minutes, bantime: 1.day) do request.path == '/429' end ... end # config/initializers/rack-attack.rb Rack::Attack.blocklisted_responder = lambda do |request| [ 429, {}, ["You are blocked. If you think are not a bot and you think it was due to a mistake, reach out to us at support@yourdomain.com"]] end The way I interpreted the article wasn't to redirect everything to a 404 page, but how to handle massive amount of requests to a 404 page!