mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
68 lines
2.4 KiB
Markdown
68 lines
2.4 KiB
Markdown
# Defensive Relay Features
|
|
|
|
**ID:** d6ee
|
|
|
|
## Issue Summary
|
|
|
|
Implement comprehensive rate limiting and resource controls to protect the relay from abuse, whether malicious or accidental. This includes connection limits, subscription limits, event rate limiting, and HTTP request throttling.
|
|
|
|
## Required Defensive Features
|
|
|
|
1. **Connection limits:**
|
|
- Max concurrent WebSocket connections per IP address
|
|
- Max concurrent WebSocket connections globally
|
|
- Connection rate limiting (new connections per time window per IP)
|
|
- Configurable limits with reasonable defaults
|
|
|
|
2. **Subscription limits:**
|
|
- Max concurrent subscriptions (REQ) per connection
|
|
- Max concurrent subscriptions per IP address
|
|
- Max filters per subscription
|
|
- Max complexity per filter (e.g., number of authors, kinds, tags)
|
|
- Subscription creation rate limiting
|
|
|
|
3. **Event ingestion rate limiting:**
|
|
- Max events per second per connection
|
|
- Max events per second per IP address
|
|
- Max event size (individual message size)
|
|
- Total bandwidth limits per connection/IP
|
|
|
|
4. **HTTP endpoint protection:**
|
|
- Rate limit all HTTP endpoints by IP
|
|
- Separate limits for different endpoint types (NIP-11 info, metrics, etc.)
|
|
- Protection against slow-loris and similar attacks
|
|
|
|
5. **Configuration:**
|
|
- All limits should be configurable
|
|
- Sensible defaults that work for most deployments
|
|
- Ability to whitelist trusted IPs/relays
|
|
- Metrics/logging for when limits are hit
|
|
|
|
## Investigation Tasks
|
|
|
|
- [ ] Review rust-nostr relay defaults and examples for rate limiting
|
|
- [ ] Check nostr-rs-relay implementation and defaults
|
|
- [ ] Research khatru (Go) relay defaults and approach
|
|
- [ ] Research pyramid relay defaults and approach
|
|
- [ ] Research strfry relay defaults and approach
|
|
- [ ] Survey other production Nostr relays for their limits
|
|
- [ ] Identify what rate limiting crates are available in Rust ecosystem
|
|
- [ ] Document common attack patterns seen by production relays
|
|
- [ ] Determine appropriate default values based on research
|
|
|
|
## Findings
|
|
|
|
*(To be filled in during investigation)*
|
|
|
|
## Implementation Plan
|
|
|
|
*(To be determined after investigation)*
|
|
|
|
## References
|
|
|
|
- rust-nostr examples: https://github.com/rust-nostr/nostr
|
|
- nostr-rs-relay: https://git.sr.ht/~gheartsfield/nostr-rs-relay
|
|
- khatru: https://github.com/fiatjaf/khatru
|
|
- strfry: https://github.com/hoytech/strfry
|
|
- pyramid: https://github.com/pyramid-network/pyramid
|