mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
2.4 KiB
2.4 KiB
Defensive Relay Features
ID: d6ee
Issue Summary
Implement comprehensive rate limiting and resource controls to protect the relay from abuse, whether malicious or accidental. This includes connection limits, subscription limits, event rate limiting, and HTTP request throttling.
Required Defensive Features
-
Connection limits:
- Max concurrent WebSocket connections per IP address
- Max concurrent WebSocket connections globally
- Connection rate limiting (new connections per time window per IP)
- Configurable limits with reasonable defaults
-
Subscription limits:
- Max concurrent subscriptions (REQ) per connection
- Max concurrent subscriptions per IP address
- Max filters per subscription
- Max complexity per filter (e.g., number of authors, kinds, tags)
- Subscription creation rate limiting
-
Event ingestion rate limiting:
- Max events per second per connection
- Max events per second per IP address
- Max event size (individual message size)
- Total bandwidth limits per connection/IP
-
HTTP endpoint protection:
- Rate limit all HTTP endpoints by IP
- Separate limits for different endpoint types (NIP-11 info, metrics, etc.)
- Protection against slow-loris and similar attacks
-
Configuration:
- All limits should be configurable
- Sensible defaults that work for most deployments
- Ability to whitelist trusted IPs/relays
- Metrics/logging for when limits are hit
Investigation Tasks
- Review rust-nostr relay defaults and examples for rate limiting
- Check nostr-rs-relay implementation and defaults
- Research khatru (Go) relay defaults and approach
- Research pyramid relay defaults and approach
- Research strfry relay defaults and approach
- Survey other production Nostr relays for their limits
- Identify what rate limiting crates are available in Rust ecosystem
- Document common attack patterns seen by production relays
- Determine appropriate default values based on research
Findings
(To be filled in during investigation)
Implementation Plan
(To be determined after investigation)
References
- rust-nostr examples: https://github.com/rust-nostr/nostr
- nostr-rs-relay: https://git.sr.ht/~gheartsfield/nostr-rs-relay
- khatru: https://github.com/fiatjaf/khatru
- strfry: https://github.com/hoytech/strfry
- pyramid: https://github.com/pyramid-network/pyramid