Changed throttle log to info level + switched to a steady clock, fixes #725
This commit is contained in:
@@ -46,7 +46,7 @@ namespace lms::auth
|
|||||||
|
|
||||||
void LoginThrottler::removeOutdatedEntries()
|
void LoginThrottler::removeOutdatedEntries()
|
||||||
{
|
{
|
||||||
const Wt::WDateTime now{ Wt::WDateTime::currentDateTime() };
|
const Clock::time_point now{ Clock::now() };
|
||||||
|
|
||||||
for (auto it{ std::begin(_attemptsInfo) }; it != std::end(_attemptsInfo);)
|
for (auto it{ std::begin(_attemptsInfo) }; it != std::end(_attemptsInfo);)
|
||||||
{
|
{
|
||||||
@@ -60,7 +60,7 @@ namespace lms::auth
|
|||||||
void LoginThrottler::onBadClientAttempt(const boost::asio::ip::address& address)
|
void LoginThrottler::onBadClientAttempt(const boost::asio::ip::address& address)
|
||||||
{
|
{
|
||||||
const boost::asio::ip::address clientAddress{ getAddressToThrottle(address) };
|
const boost::asio::ip::address clientAddress{ getAddressToThrottle(address) };
|
||||||
const Wt::WDateTime now{ Wt::WDateTime::currentDateTime() };
|
const Clock::time_point now{ Clock::now() };
|
||||||
|
|
||||||
if (_attemptsInfo.size() >= _maxEntries)
|
if (_attemptsInfo.size() >= _maxEntries)
|
||||||
removeOutdatedEntries();
|
removeOutdatedEntries();
|
||||||
@@ -68,7 +68,7 @@ namespace lms::auth
|
|||||||
_attemptsInfo.erase(core::random::pickRandom(_attemptsInfo));
|
_attemptsInfo.erase(core::random::pickRandom(_attemptsInfo));
|
||||||
|
|
||||||
AttemptInfo& attemptInfo{ _attemptsInfo[address] };
|
AttemptInfo& attemptInfo{ _attemptsInfo[address] };
|
||||||
if (attemptInfo.nextAttempt.isValid())
|
if (attemptInfo.nextAttempt != Clock::time_point{})
|
||||||
{
|
{
|
||||||
assert(attemptInfo.nextAttempt <= now); // should not be called if throttled
|
assert(attemptInfo.nextAttempt <= now); // should not be called if throttled
|
||||||
attemptInfo = {};
|
attemptInfo = {};
|
||||||
@@ -79,12 +79,12 @@ namespace lms::auth
|
|||||||
LMS_LOG(AUTH, DEBUG, "Registering bad attempt for '" << clientAddress.to_string() << "', consecutive bad attempts count = " << attemptInfo.badConsecutiveAttemptCount);
|
LMS_LOG(AUTH, DEBUG, "Registering bad attempt for '" << clientAddress.to_string() << "', consecutive bad attempts count = " << attemptInfo.badConsecutiveAttemptCount);
|
||||||
if (attemptInfo.badConsecutiveAttemptCount >= _maxBadConsecutiveAttemptCount)
|
if (attemptInfo.badConsecutiveAttemptCount >= _maxBadConsecutiveAttemptCount)
|
||||||
{
|
{
|
||||||
LMS_LOG(AUTH, DEBUG, "Throttling '" << clientAddress.to_string() << "'");
|
LMS_LOG(AUTH, INFO, "Throttling '" << clientAddress.to_string() << "' for " << std::chrono::duration_cast<std::chrono::seconds>(_throttlingDuration).count() << " seconds");
|
||||||
attemptInfo.nextAttempt = now.addMSecs(std::chrono::duration_cast<std::chrono::milliseconds>(_throttlingDuration).count());
|
attemptInfo.nextAttempt = now + _throttlingDuration;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
attemptInfo.nextAttempt = {};
|
attemptInfo.nextAttempt = Clock::time_point{};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -103,9 +103,9 @@ namespace lms::auth
|
|||||||
if (it == _attemptsInfo.end())
|
if (it == _attemptsInfo.end())
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
if (!it->second.nextAttempt.isValid())
|
if (it->second.nextAttempt == Clock::time_point{})
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
return it->second.nextAttempt > Wt::WDateTime::currentDateTime();
|
return it->second.nextAttempt > Clock::now();
|
||||||
}
|
}
|
||||||
} // namespace lms::auth
|
} // namespace lms::auth
|
||||||
@@ -22,15 +22,15 @@
|
|||||||
#include <chrono>
|
#include <chrono>
|
||||||
#include <unordered_map>
|
#include <unordered_map>
|
||||||
|
|
||||||
#include <Wt/WDateTime.h>
|
#include "core/NetAddress.hpp" // for unordered_map of boost::asio::ip::address
|
||||||
|
|
||||||
#include "core/NetAddress.hpp"
|
|
||||||
|
|
||||||
namespace lms::auth
|
namespace lms::auth
|
||||||
{
|
{
|
||||||
class LoginThrottler
|
class LoginThrottler
|
||||||
{
|
{
|
||||||
public:
|
public:
|
||||||
|
using Clock = std::chrono::steady_clock;
|
||||||
|
|
||||||
LoginThrottler(std::size_t maxEntries)
|
LoginThrottler(std::size_t maxEntries)
|
||||||
: _maxEntries{ maxEntries } {}
|
: _maxEntries{ maxEntries } {}
|
||||||
|
|
||||||
@@ -52,7 +52,7 @@ namespace lms::auth
|
|||||||
|
|
||||||
struct AttemptInfo
|
struct AttemptInfo
|
||||||
{
|
{
|
||||||
Wt::WDateTime nextAttempt;
|
Clock::time_point nextAttempt{};
|
||||||
std::size_t badConsecutiveAttemptCount{};
|
std::size_t badConsecutiveAttemptCount{};
|
||||||
};
|
};
|
||||||
std::unordered_map<boost::asio::ip::address, AttemptInfo> _attemptsInfo;
|
std::unordered_map<boost::asio::ip::address, AttemptInfo> _attemptsInfo;
|
||||||
|
|||||||
Reference in New Issue
Block a user