Page MenuHomePhabricator

hCaptcha risk scores: API endpoint rate limiting
Closed, ResolvedPublic0.5 Estimated Story Points

Description

Summary

  • Add rate limiting to the action=hcaptchariskscore API endpoint to prevent abuse.

Technical notes

  • We could use the pattern used in CheckUser's UserInfoHandler as a reference.

Acceptance Criteria

  • The endpoint is rate-limited via MW ApiBase rate limiting

Event Timeline

Change #1290031 had a related patch set uploaded (by Harroyo-wmf; author: Harroyo-wmf):

[mediawiki/extensions/ConfirmEdit@master] hCaptcha: Endpoint for collecting risk scores

https://gerrit.wikimedia.org/r/1290031

Change #1290031 merged by jenkins-bot:

[mediawiki/extensions/ConfirmEdit@master] hCaptcha: Endpoint for collecting risk scores

https://gerrit.wikimedia.org/r/1290031