GSoC 2022 project viability - adding rate-limiting to core

63 views
Skip to first unread message

Hrushikesh Vaidya

unread,
Mar 10, 2022, 10:34:03 AM3/10/22
to Django developers (Contributions to Django itself)
As per this discussion on the Django Forum, there is some concern about adding 
rate-limiting to core as a part of this year's GSoC. The project is listed on this wiki page

The main concern is, paraphrasing @claudep, that it would be very easy to introduce DoS
vectors to pretty much all Django applications if rate-limiting is not used/configured 
properly. If users currently use a third party application to implement rate-limiting, its 
security is their responsibility. But if we add rate-limiting to core, it would become our 
responsibility to make sure that we don't introduce DoS vectors to unsuspecting users' 
applications.

I would love to work on this project, but I wanted to address this risk and confirm that this 
project is still viable.
Reply all
Reply to author
Forward
0 new messages