Re: New global API rate limits deployed for anonymous requests

Travis Briggs via Wikitech-l <[email protected]> Mon, 16 Mar 2026 07:36:32 -0700
Newsgroups gmane.science.linguistics.wikipedia.technical
Message-ID <CAMPYpA6g2FQkbtG9c9gzSedHWoGYFgX+qNCrbQWqj7_07CgWGA@mail.gmail.com>
Okay yes, that definitely makes sense.

I think these policies are definitely necessary given current traffic
patterns of abuse. I am very concerned about "legacy" tools however. If
you've spent time on the cloud mailing list, it seems like there are
multiple emails each year about "unclaimed" and "abandoned" projects and
the like. General issues of code rot and maintenance aside, as Piotr
mentioned there are many tools like this that are actively and extensively
used despite not being updated for a decade. This policy might end up being
a "hard deprecation" of such tools unless there is further deliberate
consideration.

(This may be a good focus for a hackathon, but I digress.)

I understand that "Referer" is a clear abuse vector, and is intolerable
from an "airtight" security posture, but maybe the benefits in terms of not
disrupting community workflows could outweigh the risks? Perhaps we could
monitor the traffic using this "workaround" and be prepared to cut off the
exception at any time once it is discovered by bad actors? Obviously this
wouldn't work if an additional unstated goal of this effort is to actually
reduce overall usage/costs.

Thanks,
-Travis

On Mon, Mar 16, 2026 at 6:54 AM Daniel Kinzler <[email protected]>
wrote:

> Am 16.03.26 um 12:07 schrieb Travis Briggs via Wikitech-l:
>
> Great idea, I think Referer is completely reasonable as a rate limiting
> signal, because it is no worse than User-Agent from a spoofing/abuse
> perspective.
>
>
> Because the User-Agent is spoofable, we will likely stop using it as a
> rate limit key soon-ish for requests coming from outside WMCS. Sending a
> compliant user-Agent will give you a better rate limit than not doing so,
> but not a *great* limit. So adding more untrusted headers into the mix is
> not going to help
>
> In the long run, authenticating, or asking users to authenticate, will be
> the only way for apps and bots to ensure virtually unlimited API access.
> Unauthenticated traffic will generally be rate limited per IP.
>
> --
> Daniel Kinzler
> Principal Software Engineer
> MediaWiki Engineering Group
> Wikimedia Foundation
>
>
>

_______________________________________________
Wikitech-l mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/