Comment 10 for bug 963098

Revision history for this message
Rafael Durán Castañeda (rafadurancastaneda) wrote :

Hi,

Any advance about this at design summit? I've been thinking about how to solve this:
* Adding a "Security" middleware saving information about "suspicious" requests (e.g.: 4xx-5xx)
* Allow a pluggable set of "actions" based on that information. I think kesytone can't provide something that just works for everyone, since this can be quite different for every organization, and thus the most important thing is each one can easily add custom "actions".
* Provide some generic actions as example e.g.: mail to sys admins, increase delay,..
* Migrating the ratelimit middleware from Nova probably would help a lot on this

What do you think??