feat: Add rate limiting to fallback handling via token bucket (#12)

Co-authored-by: RPRX <63339210+RPRX@users.noreply.github.com>
This commit is contained in:
Meow
2025-06-08 13:11:45 +00:00
committed by GitHub
co-authored by RPRX
parent 90e738a94c
commit 4fd34dd4eb
6 changed files with 80 additions and 7 deletions
+12 -2
View File
@@ -537,6 +537,12 @@ const (
RenegotiateFreelyAsClient
)
type LimitFallback struct {
AfterBytes uint64
BytesPerSec uint64
BurstBytesPerSec uint64
}
// A Config structure is used to configure a TLS client or server.
// After one has been passed to a TLS function it must not be
// modified. A Config may be reused; the tls package will also not
@@ -556,6 +562,9 @@ type Config struct {
MaxTimeDiff time.Duration
ShortIds map[[8]byte]bool
LimitFallbackUpload LimitFallback
LimitFallbackDownload LimitFallback
// Rand provides the source of entropy for nonces and RSA blinding.
// If Rand is nil, TLS uses the cryptographic random reader in package
// crypto/rand.
@@ -913,7 +922,6 @@ type EncryptedClientHelloKey struct {
SendAsRetry bool
}
const (
// ticketKeyLifetime is how long a ticket key remains valid and can be used to
// resume a client connection.
@@ -971,6 +979,8 @@ func (c *Config) Clone() *Config {
MaxClientVer: c.MaxClientVer,
MaxTimeDiff: c.MaxTimeDiff,
ShortIds: c.ShortIds,
LimitFallbackUpload: c.LimitFallbackUpload,
LimitFallbackDownload: c.LimitFallbackDownload,
Rand: c.Rand,
Time: c.Time,
Certificates: c.Certificates,
@@ -1793,4 +1803,4 @@ func fipsAllowChain(chain []*x509.Certificate) bool {
}
return true
}
}