Project

General

Profile

Actions

Improvements #13970

closed

Kill sessioned GET requests early

Added by Matthias Van Ceulebroeck about 2 months ago. Updated 19 days ago.

Status:
Closed
Priority:
Normal
Target version:
Start date:
09/10/2025
Due date:
% Done:

100%

Estimated time:

Description

If a session comes in, that is NOT detected as a bot, and does allow JavaScript, they should never have a wtd parameter attached to them.
This can only be the case if JavaScript is disabled.

In the wild we've seen this happen, with suspected bots that are JS/Ajax capable, but still seemingly are only used to access a page singularly, not utilizing the session.
These type of sessions should be killed early, so they do not uselessly take up memory.


Related issues 1 (1 open0 closed)

Related to Improvements #13877: Be less permissive to botsNew07/29/2025

Actions
Actions #1

Updated by Matthias Van Ceulebroeck about 2 months ago

  • Status changed from InProgress to Review
  • Assignee deleted (Matthias Van Ceulebroeck)
Actions #2

Updated by Matthias Van Ceulebroeck about 2 months ago

Actions #3

Updated by Romain Mardulyn about 2 months ago

  • Assignee set to Romain Mardulyn
Actions #4

Updated by Matthias Van Ceulebroeck 20 days ago

  • Status changed from Review to Implemented @Emweb
  • Assignee changed from Romain Mardulyn to Matthias Van Ceulebroeck
  • % Done changed from 0 to 100
Actions #5

Updated by Matthias Van Ceulebroeck 20 days ago

  • Status changed from Implemented @Emweb to Implemented @Test
Actions #6

Updated by Matthias Van Ceulebroeck 19 days ago

  • Status changed from Implemented @Test to Closed
Actions

Also available in: Atom PDF