Hey there, do Ory ratelimits actually work? We've just gotten through yet another DDOS attack, which was 1 person refreshing the /login page...
plain-park-26172
10/03/2024, 11:58 AM
The only time I've seen the ratelimit work is when I'm executing an HTTP request outside the browser. It seems like whatever ratelimit rules you have going just let bad actors do whatever aslong as it's coming from a browser...
plain-park-26172
10/03/2024, 11:59 AM
And we can't enable cloudflare on Ory endpoints, per your recommendation and because it also breaks API access. When are we gonna have special ratelimit rules/whitelisted user-agents?
r
rough-winter-14513
10/07/2024, 10:52 AM
Hey,
Could you please provide more details, such as the project name and the timestamp when you experienced the issue?