mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Passwordless endpoints are rate limited because they allow unauthenticated challenge generation. The endpoint rate limits are applied in addition to (pre-existing) storage limits. Setting limits to Auth only would be sufficient, but it seems best to apply limits to Proxy as well, so we may spare Auth of unnecessary load. Auth already has a framework for RPC rate limiting, so we took advantage of it. The solution for the Proxy is rather simple - the handler is decorated with the appropriate limits. #9160 * Fix shadowing of grpcServer variable * Add rate limiting for CreateAuthenticateChallenge * Add rate limiting for /mfa/login/begin * Safe parallel tests