Page MenuHomePhabricator

Introduce a rate limit per user for malicious users
Open, Needs TriagePublic

Description

Introduce a rate limit per user- for example, there is no limit to the number of edits that can be made by a single user. See T258354 and related discussions.

Action item extracted from postmortem of incident 2025-09-19: s1 DB master overload by a single malicious user.
Incident document: https://docs.google.com/document/d/1j-1dz6L_Xt_3eF4bVOm7fK_DoD4RsuGsgB30OiOn5SE/edit?tab=t.0#heading=h.8lq88tc7h8f8

Event Timeline

@MLechvien-WMF Which codebase project tag or team tag should be added to this task, so this task appears on a workboard?

A_smart_kitten subscribed.

(half-assuming that this tag might be suitable here)

MLechvien-WMF added a subscriber: CDanis.

@CDanis as you wrote the initial Incident document linked in description, is this task still relevant, which team would be able to give an opinion here?

@CDanis: Could you please answer the last comment? Thanks in advance!