Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential DoS when requesting vanilla object information #74

Open
LeftofZen opened this issue Aug 29, 2024 · 0 comments
Open

Potential DoS when requesting vanilla object information #74

LeftofZen opened this issue Aug 29, 2024 · 0 comments

Comments

@LeftofZen
Copy link
Collaborator

The web client in the editor caches successful downloads it receives from the object repository, but since the object repository doesn't send vanilla object data (but it does index/list them) then the user can repeatedly query for these objects until the rate limiter kicks in, which is a global service and will deny any other users access for the period until tokens are replenished.

@LeftofZen LeftofZen modified the milestones: 2.4.0+, 3.0.0, 3.0.0+, 3.0.2+, Future Aug 29, 2024
@LeftofZen LeftofZen removed this from the Future milestone Sep 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant