Repository navigation
feat(opds): exponential backoff on failed authentication - #163
Merged
Merged
Conversation
Repeated failed auth attempts now trigger a global backoff: after three consecutive rejections the server answers 429 with Retry-After instead of hashing, doubling from 2s to a 60s cap. A successful authentication resets it. The state lives on the shared auth handle, so both wildcard listeners count against the same budget. This was the condition under which the ~30.5-bit generated password was accepted: with sustained guessing throttled to ~1-2 attempts per second, the margin is years.
libcalibre Test Coverage ReportOverall coverage: 80.16% Coverage breakdown available in the artifacts. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The generated password is ~30.5 bits — deliberately short because a human types it on an e-reader. That's fine only if the online attacker can't hammer the server. Today the only friction is the Argon2 verify cost (~3 concurrent, ~100ms each), which still permits sustained guessing at ~60 attempts/second: full exhaustion of 30.5 bits in ~6 months of nonstop grinding.
What this does
Global exponential backoff on consecutive rejected authentication attempts, living on the shared auth handle (both wildcard listeners count against one budget):
With sustained guessing throttled to ~1–2 attempts/second, the 30.5-bit margin becomes years. This was the condition under which the short generated password was accepted in #161.
Testing
59 tests pass, including two new: the throttle window opens after the threshold and expires back into verification, and a successful authentication resets the budget mid-streak. (The first version of this missed cached rejections — replayed wrong headers bypassed the counter; the tests caught it.)