Commit Graph
8 Commits
Author SHA1 Message Date
pmb c8786a2a0b Route finger search through the cacheable /finger/<term> path
Build and Push Docker Image / build-and-push (push) Failing after 2m19s
The search form POSTed to /finger, an uncacheable URL with no search term in
it, so every lookup re-ran the finger command even for repeated searches of the
same user. Redirect any query/POST search to the canonical /finger/<username>
path (and submit the form via GET, with a JS fast-path straight to that URL) so
repeated lookups are served from the nginx response cache. A bare /finger with
no user still lists local system users.
2026-06-17 10:24:16 -07:00
pmb 3115ac64b2 Add per-IP rate limiting to prevent finger-daemon abuse
The app sits behind nginx, which caches 200s for 30s — so repeated lookups
of the same user are cheap. What bypasses the cache is enumeration of distinct
usernames: each is a unique cache key -> miss -> a fresh finger call to the
mammut daemon, all attributed to admin's single IP (so the daemon cannot ban
the real source). The app only ever receives cache misses, so a per-IP limit
here throttles exactly that uncached path without touching the cached hot path.

- Flask-Limiter keyed per client IP: 30/min on the finger lookup endpoints,
  10/min on /api/upload (auth brute-force), 120/min global default. Index and
  the container healthcheck are exempt. All limits env-tunable (RATELIMIT_*).
- ProxyFix(x_for=1): trust nginx's X-Forwarded-For so the real client IP is
  used for keying and logging. Without it the app only saw the Docker bridge
  gateway (172.20.0.1) and every client shared one bucket.
- 429 handler (JSON for /api, HTML 429.html otherwise) and WARNING logging of
  failed/invalid lookups and limit hits, so enumeration is observable.
2026-06-17 10:23:58 -07:00
pmb ad4b9b9af8 Use minimal single-column layout for all finger results
Unify the interactive /finger page on the same results-first layout
introduced for direct /finger/<user> links: drop the two-column view
(About Finger panel, success banner, timestamp, back-to-home button)
and the now-unused direct flag.
2026-06-15 20:36:41 -07:00
pmb a49545796a Minimal single-column layout for direct /finger/<user> links
Direct links now render a results-first single-column view: drop the
About Finger panel, success banner, timestamp and back-to-home button,
and replace the lookup card with a small inline form next to the heading.
The interactive /finger page keeps its original two-column layout.
2026-06-15 20:26:55 -07:00
pmb b99636d3c0 Fix BuildError: nav links to renamed api_info endpoint
base.html referenced url_for('api_hello'), but that endpoint is now
api_info (/api/info). Since every page extends base.html, the dead
reference raised werkzeug BuildError and returned HTTP 500 site-wide --
including /finger/<user>, which federated Mastodon instances fetch for
link previews. The 500s also defeated nginx's 200-only cache, so every
fetch re-ran the finger subprocess against the daemon on mammut.
2026-06-15 17:01:56 -07:00
pmb 1576c4508b Fixed typo 2025-06-26 15:03:22 -07:00
pmb 9f1b2c2562 Changed some of the formatting etc 2025-06-26 15:00:22 -07:00
pmb b672b249a6 first commit 2025-06-26 12:44:28 -07:00