Expose remaining retry delay for rate-limited requests - #492
Conversation
| time.Now(), | ||
| ) | ||
|
|
||
| log.Infof(server.Logger, |
There was a problem hiding this comment.
move logging outside lock? disk?
Expire elapsed buckets before checking requests and during periodic cleanup. Keep one deadline per endpoint and remove server-wide timer alignment. Move rate-limit logging outside the endpoint lock and cover early ticks, missed ticks, and expiry for IP, user, and group limits.
|
|
||
| log.Infof(server.Logger, | ||
| "Rate limited request for %s %s - %s %s - count %d", | ||
| trigger, key, method, routeParsed, requestCount) |
There was a problem hiding this comment.
The rate-limit log includes key, which contains the user identifier or IP address and can identify a specific person.
Details
✨ AI Reasoning
The request-handling path assigns key from the authenticated user identifier or client IP address. The new rate-limit log includes that value in every blocked-request message, exposing data that can identify a specific person.
🔧 How do I fix it?
Keep sensitive data such as emails, passwords, and tokens out of logs. When logging values tied to a user, prefer a safe identifier like a user ID over the raw input, and strip line breaks from any user-provided text you do log.
Reply @AikidoSec feedback: [FEEDBACK] to get better review comments in the future.
Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info
There was a problem hiding this comment.
⛔ You don't have permission to ignore issues.
Expose
retry_afteronaikido\should_block_request()so middleware can includeRetry-Afterin 429 responses. It returns the remaining wait in seconds for IP, user, and group limits, ornullwhen not rate limited.Local validation: Go suites and race checks, PHP HTTP regressions, and the shared Retry-After QA test passed. Coverage includes countdowns, bucket expiry, identity isolation, and ordinary 403 responses.
Companion demo middleware.