Changed throttle log to info level + switched to a steady clock, fixes #725

This commit is contained in:
emeric
2025-08-04 19:14:01 +02:00
parent 70e86334bc
commit 9f13742a5a
2 changed files with 12 additions and 12 deletions
@@ -46,7 +46,7 @@ namespace lms::auth
void LoginThrottler::removeOutdatedEntries() void LoginThrottler::removeOutdatedEntries()
{ {
const Wt::WDateTime now{ Wt::WDateTime::currentDateTime() }; const Clock::time_point now{ Clock::now() };
for (auto it{ std::begin(_attemptsInfo) }; it != std::end(_attemptsInfo);) for (auto it{ std::begin(_attemptsInfo) }; it != std::end(_attemptsInfo);)
{ {
@@ -60,7 +60,7 @@ namespace lms::auth
void LoginThrottler::onBadClientAttempt(const boost::asio::ip::address& address) void LoginThrottler::onBadClientAttempt(const boost::asio::ip::address& address)
{ {
const boost::asio::ip::address clientAddress{ getAddressToThrottle(address) }; const boost::asio::ip::address clientAddress{ getAddressToThrottle(address) };
const Wt::WDateTime now{ Wt::WDateTime::currentDateTime() }; const Clock::time_point now{ Clock::now() };
if (_attemptsInfo.size() >= _maxEntries) if (_attemptsInfo.size() >= _maxEntries)
removeOutdatedEntries(); removeOutdatedEntries();
@@ -68,7 +68,7 @@ namespace lms::auth
_attemptsInfo.erase(core::random::pickRandom(_attemptsInfo)); _attemptsInfo.erase(core::random::pickRandom(_attemptsInfo));
AttemptInfo& attemptInfo{ _attemptsInfo[address] }; AttemptInfo& attemptInfo{ _attemptsInfo[address] };
if (attemptInfo.nextAttempt.isValid()) if (attemptInfo.nextAttempt != Clock::time_point{})
{ {
assert(attemptInfo.nextAttempt <= now); // should not be called if throttled assert(attemptInfo.nextAttempt <= now); // should not be called if throttled
attemptInfo = {}; attemptInfo = {};
@@ -79,12 +79,12 @@ namespace lms::auth
LMS_LOG(AUTH, DEBUG, "Registering bad attempt for '" << clientAddress.to_string() << "', consecutive bad attempts count = " << attemptInfo.badConsecutiveAttemptCount); LMS_LOG(AUTH, DEBUG, "Registering bad attempt for '" << clientAddress.to_string() << "', consecutive bad attempts count = " << attemptInfo.badConsecutiveAttemptCount);
if (attemptInfo.badConsecutiveAttemptCount >= _maxBadConsecutiveAttemptCount) if (attemptInfo.badConsecutiveAttemptCount >= _maxBadConsecutiveAttemptCount)
{ {
LMS_LOG(AUTH, DEBUG, "Throttling '" << clientAddress.to_string() << "'"); LMS_LOG(AUTH, INFO, "Throttling '" << clientAddress.to_string() << "' for " << std::chrono::duration_cast<std::chrono::seconds>(_throttlingDuration).count() << " seconds");
attemptInfo.nextAttempt = now.addMSecs(std::chrono::duration_cast<std::chrono::milliseconds>(_throttlingDuration).count()); attemptInfo.nextAttempt = now + _throttlingDuration;
} }
else else
{ {
attemptInfo.nextAttempt = {}; attemptInfo.nextAttempt = Clock::time_point{};
} }
} }
@@ -103,9 +103,9 @@ namespace lms::auth
if (it == _attemptsInfo.end()) if (it == _attemptsInfo.end())
return false; return false;
if (!it->second.nextAttempt.isValid()) if (it->second.nextAttempt == Clock::time_point{})
return false; return false;
return it->second.nextAttempt > Wt::WDateTime::currentDateTime(); return it->second.nextAttempt > Clock::now();
} }
} // namespace lms::auth } // namespace lms::auth
@@ -22,15 +22,15 @@
#include <chrono> #include <chrono>
#include <unordered_map> #include <unordered_map>
#include <Wt/WDateTime.h> #include "core/NetAddress.hpp" // for unordered_map of boost::asio::ip::address
#include "core/NetAddress.hpp"
namespace lms::auth namespace lms::auth
{ {
class LoginThrottler class LoginThrottler
{ {
public: public:
using Clock = std::chrono::steady_clock;
LoginThrottler(std::size_t maxEntries) LoginThrottler(std::size_t maxEntries)
: _maxEntries{ maxEntries } {} : _maxEntries{ maxEntries } {}
@@ -52,7 +52,7 @@ namespace lms::auth
struct AttemptInfo struct AttemptInfo
{ {
Wt::WDateTime nextAttempt; Clock::time_point nextAttempt{};
std::size_t badConsecutiveAttemptCount{}; std::size_t badConsecutiveAttemptCount{};
}; };
std::unordered_map<boost::asio::ip::address, AttemptInfo> _attemptsInfo; std::unordered_map<boost::asio::ip::address, AttemptInfo> _attemptsInfo;