I'd like to propose a non-breaking enhancement which would facilitate testing thresholds for flooding across all users, instead of just individual users.

Problem/Motivation

Drupal/Core/Flood enables events to be logged for specific event name and user identifier combinations, and for this data to be queried to see whether a specific user has exceeded some configured threshold for a given event (within a given time window).

That same data could also be used to see whether a threshold has been exceeded for an event irrespective of the users involved; but at present this type of query is not supported.

The intent is to allow distributed flooding scenarios to be detected using only the existing data (i.e. without the need to log additional events).

(This would not be useful in all circumstances, but there are also cases where enabling a site administrator to configure a global threshold for processing certain kinds of event would be of decided benefit.)

Proposed resolution

At present the isAllowed() method filters events by both the name of the event and the identifier of the user. If we simply omit the identifier condition from the resulting checks, we will be counting all events of the specified name within the given time window, enabling code to ascertain whether a given event is happening too frequently even when the events are issuing from different IP addresses.

The current interface documents that $identifier must be either a string or NULL (in the latter case the user's IP address is used). I propose that an additional value of FALSE -- being both appropriate to the intent, and also non-conflicting with currently-allowed values -- be allowed to signify that identifiers be ignored for that call.

(This enhancement could also be applied to the clear() method, where it would have the same meaning, therefore deleting all events for the given name irrespective of their registered identifier.)

I further note that these changes could safely be back-ported to Drupal 7. Although D7's flood_is_allowed() does not document that a non-NULL $identifier must be a string, FALSE simply doesn't work as an identifier -- the database column (D7 provides only a database-based implementation) is a varchar (non-NULL, defaulting to an empty string), and experimentally an attempt to register an event with identifier FALSE results in the identifier actually being an empty string, and flood_is_allowed() only recognises those events when called with an (explicit) empty string for $identifier.

Finally, those notes on D7 also apply directly to the DatabaseBackend in D8; and although you could get away with passing a boolean for the MemoryBackend, it would (a) violate the interface, (b) be incompatible with the DatabaseBackend, and (c) those booleans would be coerced to integers in that implementation, which could conflict with other values.

In summary, this would add a useful additional ability to the flood mechanism, providing a new use for the pre-existing flood data, and with no adverse effect on existing applications (in either Drupal 8 or Drupal 7).

Remaining tasks

* Write D8 patch
* Backport to D7

User interface changes

- None

API changes

Non-breaking additions to the isAllowed() and clear() methods of Drupal/Core/Flood, allowing $identifier === FALSE to indicate that the queries should ignore identifiers.

Comments

jweowu’s picture

Issue summary: View changes
jweowu’s picture

Issue summary: View changes

Version: 8.0.x-dev » 8.1.x-dev

Drupal 8.0.6 was released on April 6 and is the final bugfix release for the Drupal 8.0.x series. Drupal 8.0.x will not receive any further development aside from security fixes. Drupal 8.1.0-rc1 is now available and sites should prepare to update to 8.1.0.

Bug reports should be targeted against the 8.1.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.2.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.1.x-dev » 8.2.x-dev

Drupal 8.1.9 was released on September 7 and is the final bugfix release for the Drupal 8.1.x series. Drupal 8.1.x will not receive any further development aside from security fixes. Drupal 8.2.0-rc1 is now available and sites should prepare to upgrade to 8.2.0.

Bug reports should be targeted against the 8.2.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.3.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.2.x-dev » 8.3.x-dev

Drupal 8.2.6 was released on February 1, 2017 and is the final full bugfix release for the Drupal 8.2.x series. Drupal 8.2.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.3.0 on April 5, 2017. (Drupal 8.3.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.3.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.4.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.3.x-dev » 8.4.x-dev

Drupal 8.3.6 was released on August 2, 2017 and is the final full bugfix release for the Drupal 8.3.x series. Drupal 8.3.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.4.0 on October 4, 2017. (Drupal 8.4.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.4.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.5.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.4.x-dev » 8.5.x-dev

Drupal 8.4.4 was released on January 3, 2018 and is the final full bugfix release for the Drupal 8.4.x series. Drupal 8.4.x will not receive any further development aside from critical and security fixes. Sites should prepare to update to 8.5.0 on March 7, 2018. (Drupal 8.5.0-alpha1 is available for testing.)

Bug reports should be targeted against the 8.5.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.6.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

jweowu’s picture

Let's see what the testbot makes of it.

Status: Needs review » Needs work

The last submitted patch, 8: 0004-Test-FloodInterface-clear.patch, failed testing. View results

jweowu’s picture

Status: Needs work » Needs review
StatusFileSize
new14.45 KB

I thought that would probably happen. Not very useful, testbot. I'll have to mash it into a single patch for testing...

The last submitted patch, 8: 0001-Coding-standards-fixes-for-Flood.patch, failed testing. View results

Status: Needs review » Needs work

The last submitted patch, 11: drupal-flood-2472941-9-D8.patch, failed testing. View results

jweowu’s picture

Status: Needs work » Needs review
StatusFileSize
new14.47 KB

Status: Needs review » Needs work

The last submitted patch, 15: drupal-flood-2472941-15-D8.patch, failed testing. View results

jweowu’s picture

Status: Needs work » Needs review
StatusFileSize
new14.47 KB

Status: Needs review » Needs work

The last submitted patch, 17: drupal-flood-2472941-17-D8.patch, failed testing. View results

jweowu’s picture

Status: Needs work » Needs review
StatusFileSize
new14.47 KB

Status: Needs review » Needs work

The last submitted patch, 19: drupal-flood-2472941-19-D8.patch, failed testing. View results

Version: 8.5.x-dev » 8.6.x-dev

Drupal 8.5.6 was released on August 1, 2018 and is the final bugfix release for the Drupal 8.5.x series. Drupal 8.5.x will not receive any further development aside from security fixes. Sites should prepare to update to 8.6.0 on September 5, 2018. (Drupal 8.6.0-rc1 is available for testing.)

Bug reports should be targeted against the 8.6.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.7.x-dev branch. For more information see the Drupal 8 minor version schedule and the Allowed changes during the Drupal 8 release cycle.

Version: 8.6.x-dev » 8.8.x-dev

Drupal 8.6.x will not receive any further development aside from security fixes. Bug reports should be targeted against the 8.8.x-dev branch from now on, and new development or disruptive changes should be targeted against the 8.9.x-dev branch. For more information see the Drupal 8 and 9 minor version schedule and the Allowed changes during the Drupal 8 and 9 release cycles.

jweowu’s picture

Version: 8.8.x-dev » 8.9.x-dev
jweowu’s picture

StatusFileSize
new14.5 KB
jweowu’s picture

StatusFileSize
new14.56 KB

Version: 8.9.x-dev » 9.2.x-dev

Drupal 8 is end-of-life as of November 17, 2021. There will not be further changes made to Drupal 8. Bugfixes are now made to the 9.3.x and higher branches only. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.2.x-dev » 9.3.x-dev

Version: 9.3.x-dev » 9.4.x-dev

Drupal 9.3.15 was released on June 1st, 2022 and is the final full bugfix release for the Drupal 9.3.x series. Drupal 9.3.x will not receive any further development aside from security fixes. Drupal 9 bug reports should be targeted for the 9.4.x-dev branch from now on, and new development or disruptive changes should be targeted for the 9.5.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.4.x-dev » 9.5.x-dev

Drupal 9.4.9 was released on December 7, 2022 and is the final full bugfix release for the Drupal 9.4.x series. Drupal 9.4.x will not receive any further development aside from security fixes. Drupal 9 bug reports should be targeted for the 9.5.x-dev branch from now on, and new development or disruptive changes should be targeted for the 10.1.x-dev branch. For more information see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 9.5.x-dev » 11.x-dev

Drupal core is moving towards using a “main” branch. As an interim step, a new 11.x branch has been opened, as Drupal.org infrastructure cannot currently fully support a branch named main. New developments and disruptive changes should now be targeted for the 11.x branch. For more information, see the Drupal core minor version schedule and the Allowed changes during the Drupal core release cycle.

Version: 11.x-dev » main

Drupal core is now using the main branch as the primary development branch. New developments and disruptive changes should now be targeted to the main branch.

Read more in the announcement.