Rack Attack – Rails Tricks
greg.molnar.io
greg.molnar.io
This article just talks about blocking hosts that make too many requests to a 404 page (I guess because it's crawling?) and how to mitigate those using Rack Attack.
For reference: https://datatracker.ietf.org/doc/html/rfc7231#section-6.5.4
Like the following:
# config/routes.rb
get "429", to: "welcome#429", code: 429
rescue_from ActiveRecord::RecordNotFound, with: :too_many_requests
def too_many_requests
redirect_to "/warning"
end
# config/initializers/rack-attack.rb
class Rack::Attack
...
blocklist("block 429") do |request|
Allow2Ban.filter("too_many_requests-#{request.ip}", maxretry: 5, findtime: 3.minutes, bantime: 1.day) do
request.path == '/429'
end
...
end
# config/initializers/rack-attack.rb
Rack::Attack.blocklisted_responder = lambda do |request|
[ 429, {}, ["You are blocked. If you think are not a bot and you think it was due to a mistake, reach out to us at support@yourdomain.com"]]
end
The way I interpreted the article wasn't to redirect everything to a 404 page, but how to handle massive amount of requests to a 404 page!If I mistyped a URL, and just need to change one letter, now I can't because I've been redirected.
Well, almost inside the server. The server first does TLS processing, then this part, then that which the backend developers see as "the server". From a backend developer's perspective, this code runs in the zone between browser and server, where load balancers and such live. Operationally the code runs on in the same rack, probably on the same CPU, as the backend code.
DHH attitude toward modern FE toolings is insane.
DHH's presentation[1] during Rails World 2023 is quite interesting in that regard, I recommend you give it a go (start around minute 16). I am actually very excited with his vision of the web.
[0] https://turbo.hotwired.dev/ [1] https://www.youtube.com/watch?v=iqXjGiQ_D-A
The end result is still the same, just different approaches.
So only html doesn't buy this argument right ?
And do not tell me to "findMyStateFromADomNode", i don't store state in the DOM.