diff MoinMoin/config/multiconfig.py @ 6048:ee7209311a0e

surge protection for authentication (currently just for "moin" auth), updated docs/CHANGES also: improve docstrings, clean up
author Thomas Waldmann <tw AT waldmann-edv DOT de>
date Fri, 06 Jun 2014 15:52:35 +0200
parents 784455464e93
children 274a7f675261
line wrap: on
line diff
--- a/MoinMoin/config/multiconfig.py	Fri Jun 06 14:23:58 2014 +0200
+++ b/MoinMoin/config/multiconfig.py	Fri Jun 06 15:52:35 2014 +0200
@@ -858,6 +858,9 @@
         # (like photo galleries) triggering surge protection, we assign rather high limits:
         'AttachFile': (300, 30),
         'cache': (600, 30), # cache action is very cheap/efficient
+        # special stuff to prevent someone trying lots of usernames / passwords to log in:
+        'auth-ip': (10, 3600),  # same remote ip (any name)
+        'auth-name': (10, 3600),  # same name (any remote ip)
      },
      "Surge protection tries to deny clients causing too much load/traffic, see HelpOnConfiguration/SurgeProtection."),
     ('surge_lockout_time', 3600, "time [s] someone gets locked out when ignoring the warnings"),