mirror of
https://github.com/Growstuff/growstuff.git
synced 2026-09-27 16:34:59 -04:00
* Keep Rack::Attack counters in process memory Rack::Attack was storing its request counters in Rails.cache, which is memcached in production. On 2026-09-19, memcached calls were timing out in the production logs. When that happens, the counters stop working. In the same log window, one IP made 753 requests. 717 of them succeeded. The 15 per minute throttle and the 500 per day ban did not stop it. Rack::Attack now uses its own in-memory store, capped at 8 MB. Each Puma worker keeps its own counters, so the limits apply per worker. Refs #1640 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Add BLOCKED_IPS list to Rack::Attack When one crawler overloads the site, we need a fast way to block it. Rack::Attack now blocks every IP listed in the BLOCKED_IPS environment variable. The list is comma separated. Setting the variable does not need a code change. It also keeps IP addresses out of the repository. Refs #1640 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Lower the memcached socket timeout to 0.5 seconds The production cache store waited up to 1.5 seconds for each memcached call. Dalli's own default is 1 second. Dalli also retries after a failure, so one bad cache call can block a Puma thread for longer than the timeout. On 2026-09-19, the production logs showed memcached timeouts every few seconds. With only 5 threads per Puma worker, blocked threads make the site slow. Slow requests hold memory for longer. The timeout is now 0.5 seconds. A healthy memcached call takes a few milliseconds. A call that takes 0.5 seconds has failed in practice, so the request is better off skipping the cache. Refs #1640 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>