Friction

Feature request · Permissions & security · Blocks work

Built-in rate limiting needed to prevent spam and scraping

1 source thread · first seen 2022-12

Summary

A developer argues PocketBase has no rate limiting, so attackers can spam record creation, mass-create users or page through the whole database. The only option is per-route reverse proxy rules, which are hard to keep in sync.

Affects
developers of public-facing apps
Workaround
Per-route rate limiting rules in a reverse proxy

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“At the current state, PocketBase (in its bare form) would allow the creation of thousands of posts per second”

Report this item