Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
8af8da09
Commit
8af8da09
authored
5 years ago
by
Michael Kozono
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Note some JWT requests aren't rate limited
parent
24ff249d
Changes
2
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
5 additions
and
1 deletion
+5
-1
doc/security/rack_attack.md
doc/security/rack_attack.md
+2
-0
doc/user/gitlab_com/index.md
doc/user/gitlab_com/index.md
+3
-1
No files found.
doc/security/rack_attack.md
View file @
8af8da09
...
...
@@ -81,6 +81,8 @@ This limit is reset by requests that authenticate successfully. For example, 29
failed authentication requests followed by 1 successful request, followed by 29
more failed authentication requests would not trigger a ban.
JWT requests authenticated by gitlab-ci-token are excluded from this limit.
No response headers are provided.
## Settings
...
...
This diff is collapsed.
Click to expand it.
doc/user/gitlab_com/index.md
View file @
8af8da09
...
...
@@ -314,7 +314,7 @@ Source:
#### Git and container registry failed authentication ban
GitLab.com responds with HTTP status code
403
for 1 hour, if 30 failed
GitLab.com responds with HTTP status code
`403`
for 1 hour, if 30 failed
authentication requests were received in a 3-minute period from a single IP address.
This applies only to Git requests and container registry (
`/jwt/auth`
) requests
...
...
@@ -324,6 +324,8 @@ This limit is reset by requests that authenticate successfully. For example, 29
failed authentication requests followed by 1 successful request, followed by 29
more failed authentication requests would not trigger a ban.
JWT requests authenticated by gitlab-ci-token are excluded from this limit.
No response headers are provided.
### Admin Area settings
...
...
This diff is collapsed.
Click to expand it.
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment