You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Nov 1, 2023. It is now read-only.
whithout enabled clientThrottling, the whitelists are ignored.
The problem with that is that enabling clientThrottling is IMHO a security hole because this allows the hackers bypassing the throttling by sending random clientIds.
It would be great if the ClientKey white lists would work as well without enabled clientThrottling.
many thanks for the great project and your support!
best
Lukas
The text was updated successfully, but these errors were encountered:
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Hello,
I fear I found a security hole in the white list feature by ClientKeys. In order to make this configuration to work:
you have to configure this setting:
whithout enabled
clientThrottling
, the whitelists are ignored.The problem with that is that enabling
clientThrottling
is IMHO a security hole because this allows the hackers bypassing the throttling by sending random clientIds.It would be great if the ClientKey white lists would work as well without enabled clientThrottling.
many thanks for the great project and your support!
best
Lukas
The text was updated successfully, but these errors were encountered: