fix(proxy): drop request rate limiting from gamedata entirely

/gamedata/* is served straight from disk by nginx; no request hits the CMS
backend or a database, so a request-rate limit protects nothing while
costing players their icons. A room load fires hundreds of these files in
one burst, which every limit turned into visible 503s.

Removed the static zone from the gamedata locations. Traefik's
epicnabbo-gamedata router likewise carries no rateLimit middleware.
/client/ and /nitro-client/ keep theirs, and the main route keeps the
30r/s page budget plus the server-wide connection limit.

Measured: 1000 icon requests fired fully in parallel now all return 200,
while 200 parallel requests on / are still rejected.
This commit is contained in:
openhands committed 2026-10-01 17:56:48 +02:00
1 parent f0dcf440a7
commit 4e036b08d5
1 file changed
+10 -4
+10 -4
View File
@@ -194,8 +194,8 @@ server {
# Abuse limits. Deliberately NOT set at server scope: a room load and a page # Abuse limits. Deliberately NOT set at server scope: a room load and a page
# load are not the same request profile, so each location picks its own zone. # load are not the same request profile, so each location picks its own zone.
# Locations without an explicit limit_req inherit nothing and are unlimited — # /gamedata/* has no request limit at all — it is a disk cache, so limiting
# the page/API routes below carry the budget instead. # it only cost players their icons. The page routes carry the budget.
limit_conn cms_conn_per_ip 30; limit_conn cms_conn_per_ip 30;
# Traefik health-check route herstellen # Traefik health-check route herstellen
@@ -266,7 +266,10 @@ server {
add_header Cache-Control "public, max-age=300, must-revalidate"; add_header Cache-Control "public, max-age=300, must-revalidate";
access_log off; access_log off;
add_header Cache-Tag "cms-gamedata"; add_header Cache-Tag "cms-gamedata";
limit_req zone=cms_static_per_ip burst=1000 nodelay;
# Geen limit_req: gamedata is schijf-cache, geen CMS-backend. Een
# kamerladen vuurt honderden bestanden in één burst af en elke limiet
# hier leidde alleen tot zichtbaar gemiste icons.
add_header Access-Control-Allow-Origin $http_origin always; add_header Access-Control-Allow-Origin $http_origin always;
add_header Access-Control-Allow-Methods "GET, OPTIONS" always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
@@ -282,7 +285,10 @@ server {
add_header Cache-Control "public, max-age=3600, must-revalidate"; add_header Cache-Control "public, max-age=3600, must-revalidate";
access_log off; access_log off;
add_header Cache-Tag "cms-gamedata"; add_header Cache-Tag "cms-gamedata";
limit_req zone=cms_static_per_ip burst=1000 nodelay;
# Geen limit_req: gamedata is schijf-cache, geen CMS-backend. Een
# kamerladen vuurt honderden bestanden in één burst af en elke limiet
# hier leidde alleen tot zichtbaar gemiste icons.
add_header Access-Control-Allow-Origin $http_origin always; add_header Access-Control-Allow-Origin $http_origin always;
add_header Access-Control-Allow-Methods "GET, OPTIONS" always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always;