Add PublicAccessListener (priority 84) that allows rate-limited unauthenticated access to configured public paths. Authenticated users bypass this listener entirely via AcceptListener/AllowListener. New components: - PublicPathMatcher service with wildcard path matching (* and **) and optional host-prefix scoping - PublicAccessListener applying per-IP rate limiting to public paths - Separate public_limiter compound rate limiter (burst + sustained) - publicRateLimitCache pool (APCu in prod, array in tests) New env vars: - PUBLIC_PATHS (comma-separated path patterns, empty = disabled) - PUBLIC_BURST_COUNT/PUBLIC_BURST_TIME (default 100/60s) - PUBLIC_UPPER_COUNT/PUBLIC_UPPER_TIME (default 500/3600s) Tests: 52 new tests (29 unit for PublicPathMatcher, 12 unit for PublicAccessListener, 11 functional for PublicAccessFlowTest). Total: 293 tests, 605 assertions, all passing. PHP CS Fixer: 0 of 63 files need fixing. Documentation: README, CHANGELOG, ROADMAP, Caddyfile, example.env all updated with public access configuration and examples.
This commit is contained in:
@@ -43,6 +43,18 @@
|
||||
#UPPER_COUNT=10 # 10 per hour
|
||||
#UPPER_TIME=3600 # seconds (1 hour)
|
||||
|
||||
# --- public access (rate-limited, no auth required) ---
|
||||
# Comma-separated path patterns for public access. Wildcards:
|
||||
# * matches any chars within one path segment (not crossing /)
|
||||
# ** matches any chars including / (crosses path segments)
|
||||
# Optional host prefix: host.example.com/path/**
|
||||
# When empty (default), the feature is fully disabled.
|
||||
#PUBLIC_PATHS=''
|
||||
#PUBLIC_BURST_COUNT=100 # max requests per burst window per IP
|
||||
#PUBLIC_BURST_TIME=60 # burst window in seconds
|
||||
#PUBLIC_UPPER_COUNT=500 # max requests per sustained window per IP
|
||||
#PUBLIC_UPPER_TIME=3600 # sustained window in seconds (1 hour)
|
||||
|
||||
# --- styling options ---
|
||||
|
||||
#TITLE='Pre-Authentication System'
|
||||
|
||||
Reference in New Issue
Block a user