INNER CODE UNIT · Python
_reject
cipi-sh/cipi · lib/cipi-crowdsec-rescue.py:149
def _reject(self, ip: str) -> None:
# The throttle applies to wrong tokens only. A correct 256-bit token is
# always honoured: this is the path someone locked out of SSH uses, and
# refusing it because they fat-fingered the URL twice defeats the point.
_rate_hit(ip)
self._send(429 if not _rate_ok(ip) else 403, "forbidden\n")
def do_GET(self) -> None:
ip = _peer_ip(self)
if ip in ("127.0.0.1", "::1", ""):
self._send(403, "forbidden\n")
return
path = self.path.split("?", 1)[0]
token = path.lstrip("/")
if not TOKEN_RE.match(token):
self._reject(ip)
return
try: