authn
authn copied to clipboard
Throttling for Abusable Endpoints
trafficstars
Throttling for every endpoint that leaks information about users in the system or can be used to incur costs to the business (e.g. SMS). A well-designed throttling plan should leave normal users unaffected while slowing and eventually auto-banning attackers.
The Rack::Attack middleware could handle this part very well.
Yes, absolutely!