Skip to content
122 linesCodeBlameRaw
1/**
2 * The front door's rate limits (workers/app.ts), per request before it is
3 * answered. The bindings and their limits are in `RATE_LIMITS`
4 * (packages/contracts/src/rate-limits.ts); CONTRIBUTING.md, "Rate limits",
5 * says how they are kept.
6 *
7 * - Git over HTTPS: without credentials, by address; with them, by a hash
8 * of the credential, much higher. A clone is about three requests.
9 * - Pages: every request that reaches the Worker counts against a ceiling
10 * per address. Signed out, by address, with a tighter limit on what is
11 * costly to answer (archives, run pages, logs, search). Signed in, by a
12 * hash of the session cookie, higher: the session is not checked here,
13 * which would cost a call to identity, and the ceiling per address keeps
14 * made-up cookies from getting round the signed-out limit. With an
15 * access token (`Authorization: Bearer`, app/lib/website-token.ts), by a
16 * hash of the token, at the API's limit for a token; the address ceiling
17 * applies as for cookies.
18 *
19 * Static assets never reach the Worker (the assets binding answers them),
20 * and the few files it serves itself are left out here too. Every limit
21 * fails open.
22 */
23import {
24 type RateLimitBinding,
25 checkLimit,
26 clientAddress,
27 secretKey,
28 tooManyRequests,
29} from "@g1t/contracts/rate-limits";
30
31export type FrontDoorLimits = {
32 WEB_ANONYMOUS_LIMIT?: RateLimitBinding;
33 WEB_HEAVY_LIMIT?: RateLimitBinding;
34 WEB_SESSION_LIMIT?: RateLimitBinding;
35 WEB_ADDRESS_LIMIT?: RateLimitBinding;
36 WEB_TOKEN_LIMIT?: RateLimitBinding;
37 GIT_ANONYMOUS_LIMIT?: RateLimitBinding;
38 GIT_SIGNED_LIMIT?: RateLimitBinding;
39};
40
41/** Files the Worker serves that are never limited: build output, fonts, and top-level files such as robots.txt. */
42const UNLIMITED = /^\/(?:assets\/|fonts\/|favicon|[^/]+\.(?:ico|png|svg|txt|xml|webmanifest)$)/;
43
44/** What is costly to answer for a signed-out visitor: a repository's archives, a run's page, logs and artifacts, and search. */
45const HEAVY =
46 /^\/(?:search(?:\.data)?$|[^/]+\/[^/]+\/(?:archive\/|actions\/runs\/[^/]+(?:\.data|\/logs\.zip|\/artifacts\/[^/]+)?$|actions\/jobs\/[^/]+\/log))/;
47
48export function unlimited(pathname: string): boolean {
49 return UNLIMITED.test(pathname);
50}
51
52export function heavy(pathname: string): boolean {
53 return HEAVY.test(pathname);
54}
55
56/** The session cookie's value, or null when signed out. */
57export function sessionCookie(cookie: string | null): string | null {
58 const match = /(?:^|;\s*)g1t_session=([^;]+)/.exec(cookie ?? "");
59 return match?.[1] ?? null;
60}
61
62const GIT_MESSAGE_ANONYMOUS =
63 "Too many git requests from your network. Wait a minute and try again, or use credentials for a higher limit: https://docs.g1t.sh/reference/rate-limits/\n";
64const GIT_MESSAGE_SIGNED = "Too many git requests with these credentials. Wait a minute and try again: https://docs.g1t.sh/reference/rate-limits/\n";
65const PAGE_MESSAGE = "Too many requests from your network. Wait a minute and try again.\n";
66const TOKEN_PAGE_MESSAGE = "Too many requests with this access token. Wait a minute and try again: https://docs.g1t.sh/reference/rate-limits/\n";
67
68/**
69 * The 429 for a git request past its limit, or null to go on. Git shows a
70 * plain-text answer's body to the person running it.
71 */
72export async function gitLimited(env: FrontDoorLimits, request: Request): Promise<Response | null> {
73 const credentials = request.headers.get("authorization");
74 if (credentials) {
75 const verdict = await checkLimit(env.GIT_SIGNED_LIMIT, await secretKey("git", credentials));
76 return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_SIGNED) : null;
77 }
78 const verdict = await checkLimit(env.GIT_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`);
79 return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_ANONYMOUS) : null;
80}
81
82/**
83 * The token in a page request's `Authorization: Bearer` header, or null
84 * (app/lib/website-token.ts). Not checked here either.
85 */
86export function websiteToken(authorization: string | null): string | null {
87 return /^\s*bearer\s+(\S+)\s*$/i.exec(authorization ?? "")?.[1] ?? null;
88}
89
90/** The 429 for a page or data request past its limit, or null to go on. */
91export async function pageLimited(env: FrontDoorLimits, request: Request, pathname: string): Promise<Response | null> {
92 if (unlimited(pathname)) return null;
93 const address = `ip:${clientAddress(request)}`;
94 const token = websiteToken(request.headers.get("authorization"));
95 const session = sessionCookie(request.headers.get("cookie"));
96 const checks: Promise<string>[] = [checkLimit(env.WEB_ADDRESS_LIMIT, address)];
97 if (token) {
98 // A token on the website: per token, as the API counts it.
99 checks.push(secretKey("token", token).then((key) => checkLimit(env.WEB_TOKEN_LIMIT, key)));
100 } else if (session) {
101 checks.push(secretKey("session", session).then((key) => checkLimit(env.WEB_SESSION_LIMIT, key)));
102 } else {
103 checks.push(checkLimit(env.WEB_ANONYMOUS_LIMIT, address));
104 if (heavy(pathname)) checks.push(checkLimit(env.WEB_HEAVY_LIMIT, address));
105 }
106 const verdicts = await Promise.all(checks);
107 if (!verdicts.includes("limited")) return null;
108 if (token && verdicts[1] === "limited") return tooManyRequests(TOKEN_PAGE_MESSAGE);
109 return tooManyRequests(token || session ? PAGE_MESSAGE : `${PAGE_MESSAGE.trimEnd()} Signed-in accounts have a higher limit.\n`);
110}
111
112/**
113 * The 429 for a repository file on the usercontent origin past its limit,
114 * or null to go on. Nothing there is signed in (it never sees the session
115 * cookie), so a file counts as a signed-out page from its address. Avatars
116 * and custom emoji are answered from cache and are not limited.
117 */
118export async function usercontentLimited(env: FrontDoorLimits, request: Request, path: string): Promise<Response | null> {
119 if (path.startsWith("/avatars/") || path.startsWith("/emoji/")) return null;
120 const verdict = await checkLimit(env.WEB_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`);
121 return verdict === "limited" ? tooManyRequests(PAGE_MESSAGE) : null;
122}