Skip to content
103 linesCodeBlameRaw
1/**
2 * The front door's rate limits (workers/app.ts), per request before it is
3 * answered. The bindings and their limits are in `RATE_LIMITS`
4 * (packages/contracts/src/rate-limits.ts); docs/RATE-LIMITS.md says why.
5 *
6 * - Git over HTTPS: without credentials, by address; with them, by a hash
7 * of the credential, much higher. A clone is about three requests.
8 * - Pages: every request that reaches the Worker counts against a ceiling
9 * per address. Signed out, by address, with a tighter limit on what is
10 * costly to answer (archives, run pages, logs, search). Signed in, by a
11 * hash of the session cookie, higher: the session is not checked here,
12 * which would cost a call to identity, and the ceiling per address keeps
13 * made-up cookies from getting round the signed-out limit.
14 *
15 * Static assets never reach the Worker (the assets binding answers them),
16 * and the few files it serves itself are left out here too. Every limit
17 * fails open.
18 */
19import {
20 type RateLimitBinding,
21 checkLimit,
22 clientAddress,
23 secretKey,
24 tooManyRequests,
25} from "@g1t/contracts/rate-limits";
26
27export type FrontDoorLimits = {
28 WEB_ANONYMOUS_LIMIT?: RateLimitBinding;
29 WEB_HEAVY_LIMIT?: RateLimitBinding;
30 WEB_SESSION_LIMIT?: RateLimitBinding;
31 WEB_ADDRESS_LIMIT?: RateLimitBinding;
32 GIT_ANONYMOUS_LIMIT?: RateLimitBinding;
33 GIT_SIGNED_LIMIT?: RateLimitBinding;
34};
35
36/** Files the Worker serves that are never limited: build output, fonts, and top-level files such as robots.txt. */
37const UNLIMITED = /^\/(?:assets\/|fonts\/|favicon|[^/]+\.(?:ico|png|svg|txt|xml|webmanifest)$)/;
38
39/** What is costly to answer for a signed-out visitor: a repository's archives, a run's page, logs and artifacts, and search. */
40const HEAVY =
41 /^\/(?:search(?:\.data)?$|[^/]+\/[^/]+\/(?:archive\/|actions\/runs\/[^/]+(?:\.data|\/logs\.zip|\/artifacts\/[^/]+)?$|actions\/jobs\/[^/]+\/log))/;
42
43export function unlimited(pathname: string): boolean {
44 return UNLIMITED.test(pathname);
45}
46
47export function heavy(pathname: string): boolean {
48 return HEAVY.test(pathname);
49}
50
51/** The session cookie's value, or null when signed out. */
52export function sessionCookie(cookie: string | null): string | null {
53 const match = /(?:^|;\s*)g1t_session=([^;]+)/.exec(cookie ?? "");
54 return match?.[1] ?? null;
55}
56
57const GIT_MESSAGE_ANONYMOUS =
58 "Too many git requests from your network. Wait a minute and try again, or use credentials for a higher limit: https://docs.g1t.sh/reference/rate-limits/\n";
59const GIT_MESSAGE_SIGNED = "Too many git requests with these credentials. Wait a minute and try again: https://docs.g1t.sh/reference/rate-limits/\n";
60const PAGE_MESSAGE = "Too many requests from your network. Wait a minute and try again.\n";
61
62/**
63 * The 429 for a git request past its limit, or null to go on. Git shows a
64 * plain-text answer's body to the person running it.
65 */
66export async function gitLimited(env: FrontDoorLimits, request: Request): Promise<Response | null> {
67 const credentials = request.headers.get("authorization");
68 if (credentials) {
69 const verdict = await checkLimit(env.GIT_SIGNED_LIMIT, await secretKey("git", credentials));
70 return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_SIGNED) : null;
71 }
72 const verdict = await checkLimit(env.GIT_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`);
73 return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_ANONYMOUS) : null;
74}
75
76/** The 429 for a page or data request past its limit, or null to go on. */
77export async function pageLimited(env: FrontDoorLimits, request: Request, pathname: string): Promise<Response | null> {
78 if (unlimited(pathname)) return null;
79 const address = `ip:${clientAddress(request)}`;
80 const session = sessionCookie(request.headers.get("cookie"));
81 const checks: Promise<string>[] = [checkLimit(env.WEB_ADDRESS_LIMIT, address)];
82 if (session) {
83 checks.push(secretKey("session", session).then((key) => checkLimit(env.WEB_SESSION_LIMIT, key)));
84 } else {
85 checks.push(checkLimit(env.WEB_ANONYMOUS_LIMIT, address));
86 if (heavy(pathname)) checks.push(checkLimit(env.WEB_HEAVY_LIMIT, address));
87 }
88 const verdicts = await Promise.all(checks);
89 if (!verdicts.includes("limited")) return null;
90 return tooManyRequests(session ? PAGE_MESSAGE : `${PAGE_MESSAGE.trimEnd()} Signed-in accounts have a higher limit.\n`);
91}
92
93/**
94 * The 429 for a repository file on the usercontent origin past its limit,
95 * or null to go on. Nothing there is signed in (it never sees the session
96 * cookie), so a file counts as a signed-out page from its address. Avatars
97 * are answered from cache and are not limited.
98 */
99export async function usercontentLimited(env: FrontDoorLimits, request: Request, path: string): Promise<Response | null> {
100 if (path.startsWith("/avatars/")) return null;
101 const verdict = await checkLimit(env.WEB_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`);
102 return verdict === "limited" ? tooManyRequests(PAGE_MESSAGE) : null;
103}