Feature request · Permissions & security · Blocks work
Built-in rate limiting needed to prevent spam and scraping
1 source thread · first seen 2022-12
Summary
A developer argues PocketBase has no rate limiting, so attackers can spam record creation, mass-create users or page through the whole database. The only option is per-route reverse proxy rules, which are hard to keep in sync.
- Affects
- developers of public-facing apps
- Workaround
- Per-route rate limiting rules in a reverse proxy
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“At the current state, PocketBase (in its bare form) would allow the creation of thousands of posts per second”