The load tests (#133) sent forty clients' wrong passwords to /api/login, 54 attempts a second, which takes no account. Everyone else's requests took 4s (median 3.96s for /api/feeds, about 20ms otherwise) and `ipx status`, the healthcheck, 1.3s (#137): each attempt was an Argon2id check, tens of milliseconds of CPU, run inside the handler on one of the runtime's workers, so a handful at once held every worker the rest of the server answers on. And a wrong password for an account's name was refused a median 31ms later than one for a made-up name (#138), since only a name with a hash was checked: the answer read the same, the time said which names are accounts. auth::check_password runs the check on the blocking pool, at most half the cores at once, so a flood waits on itself, and checks a name with no account, or no password, against a fixed decoy hash, false in the same time. Under the same flood the rest of the site answers at p95 57ms, `ipx status` at most 90ms, the gap is 0.2ms, and twice as many attempts are answered. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -11,6 +11,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
- Checking every feed no longer makes every icon in the feed list flash while it runs: the list keeps the icons it has already drawn.
|
||||
|
||||
### Security
|
||||
|
||||
- A flood of sign-in attempts no longer stalls the site for everyone else. Passwords are checked a few at a time, away from the threads that answer every other request; forty wrong passwords at a time made everything else take four seconds.
|
||||
- A wrong password is refused in the same time whether or not the name is an account here, so how long it takes no longer tells anyone which names are.
|
||||
|
||||
## [0.10.0] - 2026-10-05
|
||||
|
||||
### Added
|
||||
|
||||
Reference in New Issue
Block a user