Abuse controls appear effective in one environment and …
A rate limiter on login works against direct traffic but not
The threshold is low and still bypassed because the source identity header is no longer authoritative on one route.
시나리오
단서
구독하면 이어서 볼 수 있어요
이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.
먼저 볼 것
점검 체크리스트
복구와 재발 방지
같이 보면 좋은 질문
현장에서 본 비슷한 케이스