Actions
Bug #3540
closedplain HTML sessions limit bug
Start date:
08/22/2014
Due date:
% Done:
0%
Estimated time:
Description
src/web/WebController.C:
return plainHtmlSessions_ > conf*.maxPlainSessionsRatio() * ajaxSessions*;
should be
return plainHtmlSessions_ > conf*.maxPlainSessionsRatio() * (ajaxSessions* + plainHtmlSessions_);
Currently, even if plain-ajax-sessions-ratio-limit=1, running 20 Ajax + 20 HTML sessions, new HTML sessions are discarded as DDoS.
Updated by Koen Deforche about 10 years ago
- Status changed from New to Resolved
- Assignee set to Koen Deforche
- Target version set to 3.3.4
Updated by Koen Deforche about 10 years ago
- Status changed from Resolved to Closed
Actions