aboutsummaryrefslogtreecommitdiffstats
path: root/lib/private/Security/RateLimiting/Limiter.php
blob: b7ac26d91329b7e0d50361d88414a9e8998fa2af (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
<?php

declare(strict_types=1);

/**
 * SPDX-FileCopyrightText: 2017 Nextcloud GmbH and Nextcloud contributors
 * SPDX-License-Identifier: AGPL-3.0-or-later
 */
namespace OC\Security\RateLimiting;

use OC\Security\Normalizer\IpAddress;
use OC\Security\RateLimiting\Backend\IBackend;
use OC\Security\RateLimiting\Exception\RateLimitExceededException;
use OCP\IUser;
use OCP\Security\RateLimiting\ILimiter;

class Limiter implements ILimiter {
	public function __construct(
		private IBackend $backend,
	) {
	}

	/**
	 * @param int $period in seconds
	 * @throws RateLimitExceededException
	 */
	private function register(
		string $methodIdentifier,
		string $userIdentifier,
		int $period,
		int $limit,
	): void {
		$existingAttempts = $this->backend->getAttempts($methodIdentifier, $userIdentifier);
		if ($existingAttempts >= $limit) {
			throw new RateLimitExceededException();
		}

		$this->backend->registerAttempt($methodIdentifier, $userIdentifier, $period);
	}

	/**
	 * Registers attempt for an anonymous request
	 *
	 * @param int $anonPeriod in seconds
	 * @throws RateLimitExceededException
	 */
	public function registerAnonRequest(
		string $identifier,
		int $anonLimit,
		int $anonPeriod,
		string $ip,
	): void {
		$ipSubnet = (new IpAddress($ip))->getSubnet();

		$anonHashIdentifier = hash('sha512', 'anon::' . $identifier . $ipSubnet);
		$this->register($identifier, $anonHashIdentifier, $anonPeriod, $anonLimit);
	}

	/**
	 * Registers attempt for an authenticated request
	 *
	 * @param int $userPeriod in seconds
	 * @throws RateLimitExceededException
	 */
	public function registerUserRequest(
		string $identifier,
		int $userLimit,
		int $userPeriod,
		IUser $user,
	): void {
		$userHashIdentifier = hash('sha512', 'user::' . $identifier . $user->getUID());
		$this->register($identifier, $userHashIdentifier, $userPeriod, $userLimit);
	}
}