Skip to content

Conversation

tycho
Copy link
Contributor

@tycho tycho commented Sep 29, 2025

My gitea server uses REQUIRE_SIGNIN_VIEW = expensive. These are some routes that were being hit by bots repeatedly in an apparent attempt to denial-of-service my gitea server. Both of them were triggering git invocations under the hood, so they really should be in the list of expensive routes. Adding them to the list helped in my situation, so I'm making a PR with these in case it helps others.

Signed-off-by: Steven Noonan <steven@uplinklabs.net>
@GiteaBot GiteaBot added the lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. label Sep 29, 2025
@github-actions github-actions bot added the modifies/go Pull requests that update Go code label Sep 29, 2025
@GiteaBot GiteaBot added lgtm/need 1 This PR needs approval from one additional maintainer to be merged. and removed lgtm/need 2 This PR needs two approvals by maintainers to be considered for merging. labels Sep 29, 2025
@GiteaBot GiteaBot added lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. and removed lgtm/need 1 This PR needs approval from one additional maintainer to be merged. labels Sep 29, 2025
@wxiaoguang wxiaoguang merged commit c5332fd into go-gitea:main Sep 29, 2025
26 checks passed
@GiteaBot GiteaBot added this to the 1.26.0 milestone Sep 29, 2025
rossigee pushed a commit to rossigee/gitea that referenced this pull request Oct 2, 2025
Signed-off-by: Steven Noonan <steven@uplinklabs.net>
rossigee pushed a commit to rossigee/gitea that referenced this pull request Oct 4, 2025
Signed-off-by: Steven Noonan <steven@uplinklabs.net>
zjjhot added a commit to zjjhot/gitea that referenced this pull request Oct 5, 2025
* giteaofficial/main:
  fix: auto-expand and auto-scroll for actions logs (go-gitea#35570) (go-gitea#35583)
  [skip ci] Updated translations via Crowdin
  [skip ci] Updated translations via Crowdin
  Fix creating pull request failure when the target branch name is the same as some tag (go-gitea#35552)
  Use bundled version of spectral (go-gitea#35573)
  Add rebase push display wrong comments bug (go-gitea#35560)
  Address some CodeQL security concerns (go-gitea#35572)
  fix(webhook): prevent tag events from bypassing branch filters targets go-gitea#35449 (go-gitea#35567)
  Added button to copy file name in PR files (go-gitea#35509)
  Update JS and PY deps (go-gitea#35565)
  Enable a few more tsconfig options (go-gitea#35553)
  Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (go-gitea#35557)
  add more routes to the "expensive" list (go-gitea#35547)
  Drop json-iterator dependency (go-gitea#35544)
  Add proper error message if session provider can not be created (go-gitea#35520)
  use experimental go json v2 library (go-gitea#35392)
  Use global lock instead of status pool for cron lock (go-gitea#35507)
  Move some functions to gitrepo package (go-gitea#35503)
  Move GetDiverging functions to gitrepo (go-gitea#35524)
  [skip ci] Updated translations via Crowdin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
lgtm/done This PR has enough approvals to get merged. There are no important open reservations anymore. modifies/go Pull requests that update Go code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants