Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-15 Thread Andrea Giudiceandrea via QGIS-Developer

Il 15/05/2024 11:11, Tim Sutton ha scritto:
The page is by Klas Karlsson and features only his own work, so 
perfectly legitimate. Klas is probably the most prolific contributor the 
style hub


Great! Thanks for the clarification.

Regards.

Andrea
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-15 Thread Tim Sutton via QGIS-Developer
Last note: we have also made some other config tweaks (thanks Lova!) that
should keep the site responsive for now:

https://github.com/qgis/QGIS-Django/pull/403/files#diff-5a78fbaa554f856acb6f21c8763007068d8b19b4d40e83715c379204a7011288R88
https://github.com/qgis/QGIS-Django/pull/403/files#diff-546da9eb17742d02076338cf2ce4fbc4bb0449df7f89238466af05dee65b9c4cR21
https://github.com/qgis/QGIS-Django/pull/403/files#diff-546da9eb17742d02076338cf2ce4fbc4bb0449df7f89238466af05dee65b9c4cR10

Regards

Tim


On Wed, May 15, 2024 at 10:03 AM Tim Sutton  wrote:

> Hi all
>
> So our fix proposal is here:
>
> https://github.com/qgis/QGIS-Django/issues/402
>
> I don't think chasing IP addresses is a productive way to deal with it -
> you end up playing whack-a-mole. I think our approach should cover most
> cases. A really dedicated person could emulate the QGIS user agent but I
> think that will be uncommon.
>
> Regards
>
> Tim
>
> On Wed, May 15, 2024 at 9:54 AM Julien Moura (Oslandia) via QGIS-Developer
>  wrote:
>
>> Hi Tim,
>>
>> Can you share more details about this? Do you have a HTTP referrer, IP
>> or user-agent or anything else in particular to blame?
>>
>> Regards,
>> Julien
>>
>> Le 15/05/2024 à 02:12, Andrea Giudiceandrea via QGIS-Developer a écrit :
>> > Il 15/05/2024 01:25, Tim Sutton via QGIS-Developer ha scritto:
>> >> We have been experiencing a very high load on the plugins server.
>> >
>> > Hi Tim,
>> > recently Salvatore Fiandaca spotted a website at
>> > http://qgis-hub.fast-page.org/ (only http) claiming to be a QGIS Hub
>> > for collections of free to use QGIS style xml-files and layout
>> qpt-files.
>> > Is it managed by QGIS.org or somebody known? If not, may it have
>> > something to do with the plugins server issues (someone scraping
>> > styles/layouts/plugins)?
>> >
>> > Regards.
>> >
>> > Andrea
>> > ___
>> > QGIS-Developer mailing list
>> > QGIS-Developer@lists.osgeo.org
>> > List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>> > Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>> ___
>> QGIS-Developer mailing list
>> QGIS-Developer@lists.osgeo.org
>> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>>
>
>
> --
>
> --
> ​
>
> Tim Sutton
> Kartoza Co-Founder
> Visit http://kartoza.com to find out about open source:
>  * Desktop GIS programming services
>  * Geospatial web development
> * GIS Training
> * Consulting Services
> Tim is a member of the QGIS Project Steering Committee
>
> ---
>


-- 
--
​

Tim Sutton
Kartoza Co-Founder
Visit http://kartoza.com to find out about open source:
 * Desktop GIS programming services
 * Geospatial web development
* GIS Training
* Consulting Services
Tim is a member of the QGIS Project Steering Committee
---
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-15 Thread Tim Sutton via QGIS-Developer
Hi

Maybe this would have been better in a new thread.see below for
reply

On Wed, May 15, 2024 at 1:12 AM Andrea Giudiceandrea via QGIS-Developer <
qgis-developer@lists.osgeo.org> wrote:

> Il 15/05/2024 01:25, Tim Sutton via QGIS-Developer ha scritto:
> > We have been experiencing a very high load on the plugins server.
>
> Hi Tim,
> recently Salvatore Fiandaca spotted a website at
> http://qgis-hub.fast-page.org/ (only http) claiming to be a QGIS Hub for
> collections of free to use QGIS style xml-files and layout qpt-files.
> Is it managed by QGIS.org or somebody known? If not, may it have
> something to do with the plugins server issues (someone scraping
> styles/layouts/plugins)?
>


I took a look, the site source is here:
https://github.com/style-hub/hub-server

The page is by Klas Karlsson and features only his own work, so
perfectly legitimate. Klas is probably the most prolific contributor the
style hub at
https://plugins.qgis.org/styles/?order_by=-upload_date&&is_gallery=true and
well respected (by me anyway, I am sure the rest of the QGIS community too).

We do have a plan to split the official QGIS resources plugin from the
aforementioned link into its own web site and will try to make it a
beautiful experience, taking hints from Klas' work where needed.

Thanks!

Regards

Tim




>
> Regards.
>
> Andrea
> ___
> QGIS-Developer mailing list
> QGIS-Developer@lists.osgeo.org
> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>


-- 
--

Tim Sutton
Kartoza Co-Founder
Visit http://kartoza.com to find out about open source:
 * Desktop GIS programming services
 * Geospatial web development
* GIS Training
* Consulting Services
Tim is a member of the QGIS Project Steering Committee
---
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-15 Thread Tim Sutton via QGIS-Developer
Hi all

So our fix proposal is here:

https://github.com/qgis/QGIS-Django/issues/402

I don't think chasing IP addresses is a productive way to deal with it -
you end up playing whack-a-mole. I think our approach should cover most
cases. A really dedicated person could emulate the QGIS user agent but I
think that will be uncommon.

Regards

Tim

On Wed, May 15, 2024 at 9:54 AM Julien Moura (Oslandia) via QGIS-Developer <
qgis-developer@lists.osgeo.org> wrote:

> Hi Tim,
>
> Can you share more details about this? Do you have a HTTP referrer, IP
> or user-agent or anything else in particular to blame?
>
> Regards,
> Julien
>
> Le 15/05/2024 à 02:12, Andrea Giudiceandrea via QGIS-Developer a écrit :
> > Il 15/05/2024 01:25, Tim Sutton via QGIS-Developer ha scritto:
> >> We have been experiencing a very high load on the plugins server.
> >
> > Hi Tim,
> > recently Salvatore Fiandaca spotted a website at
> > http://qgis-hub.fast-page.org/ (only http) claiming to be a QGIS Hub
> > for collections of free to use QGIS style xml-files and layout qpt-files.
> > Is it managed by QGIS.org or somebody known? If not, may it have
> > something to do with the plugins server issues (someone scraping
> > styles/layouts/plugins)?
> >
> > Regards.
> >
> > Andrea
> > ___
> > QGIS-Developer mailing list
> > QGIS-Developer@lists.osgeo.org
> > List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> > Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> ___
> QGIS-Developer mailing list
> QGIS-Developer@lists.osgeo.org
> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
>


-- 
--
​

Tim Sutton
Kartoza Co-Founder
Visit http://kartoza.com to find out about open source:
 * Desktop GIS programming services
 * Geospatial web development
* GIS Training
* Consulting Services
Tim is a member of the QGIS Project Steering Committee
---
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-15 Thread Julien Moura (Oslandia) via QGIS-Developer

Hi Tim,

Can you share more details about this? Do you have a HTTP referrer, IP 
or user-agent or anything else in particular to blame?


Regards,
Julien

Le 15/05/2024 à 02:12, Andrea Giudiceandrea via QGIS-Developer a écrit :

Il 15/05/2024 01:25, Tim Sutton via QGIS-Developer ha scritto:
We have been experiencing a very high load on the plugins server. 


Hi Tim,
recently Salvatore Fiandaca spotted a website at 
http://qgis-hub.fast-page.org/ (only http) claiming to be a QGIS Hub 
for collections of free to use QGIS style xml-files and layout qpt-files.
Is it managed by QGIS.org or somebody known? If not, may it have 
something to do with the plugins server issues (someone scraping 
styles/layouts/plugins)?


Regards.

Andrea
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


OpenPGP_0x5375CD81333F311E.asc
Description: OpenPGP public key
BEGIN:VCARD
VERSION:4.0
N:Moura;Julien;;;
FN:Julien Moura (Oslandia)
NICKNAME:jmoura
EMAIL;PREF=1;TYPE=work:julien.mo...@oslandia.com
EMAIL:juli...@oslandia.com
TZ:Europe/Paris
URL;TYPE=work:https://oslandia.com/
URL:https://geotribu.fr/
ORG:Oslandia
END:VCARD


OpenPGP_signature.asc
Description: OpenPGP digital signature
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-14 Thread Andrea Giudiceandrea via QGIS-Developer

Il 15/05/2024 01:25, Tim Sutton via QGIS-Developer ha scritto:
We have been experiencing a very high load on the plugins server. 


Hi Tim,
recently Salvatore Fiandaca spotted a website at 
http://qgis-hub.fast-page.org/ (only http) claiming to be a QGIS Hub for 
collections of free to use QGIS style xml-files and layout qpt-files.
Is it managed by QGIS.org or somebody known? If not, may it have 
something to do with the plugins server issues (someone scraping 
styles/layouts/plugins)?


Regards.

Andrea
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-14 Thread Nyall Dawson via QGIS-Developer
On Wed, 15 May 2024 at 09:33, Greg Troxel via QGIS-Developer <
qgis-developer@lists.osgeo.org> wrote:
>
>   [high plugin load]
>
> Three suggestions:
>
>   is this a distributed problem, or a few abusive addresses?  In
>   openstreetmap I think they would just firewall the addresses in
>   questio.
>
>   please don't use google recapcha or anything else without stellar
>   privacy policies

Does recaptcha even do ANYTHING anymore?  (apart from making us all train
Google's machine learning tools... 😱). I suspect the rise of chatgpt et al
has made their "protections" meaningless.

Nyall


>
>   consider rate-limiting IP addresses instead, 1s delay for a few, then
>   30s or something like that.
> ___
> QGIS-Developer mailing list
> QGIS-Developer@lists.osgeo.org
> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


Re: [QGIS-Developer] High load on plugins.qgis.org

2024-05-14 Thread Greg Troxel via QGIS-Developer
  [high plugin load]

Three suggestions:

  is this a distributed problem, or a few abusive addresses?  In
  openstreetmap I think they would just firewall the addresses in
  questio.

  please don't use google recapcha or anything else without stellar
  privacy policies

  consider rate-limiting IP addresses instead, 1s delay for a few, then
  30s or something like that.
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer


[QGIS-Developer] High load on plugins.qgis.org

2024-05-14 Thread Tim Sutton via QGIS-Developer
Hi all

We have been experiencing a very high load on the plugins server. Despite
moving to a more plugins server the problem is ongoing. We plan to add some
rules that require a captcha or similar if you want to download the zip
files for plugins from the web site (i.e. if the user agent is not QGIS
Desktop), which will hopefully reduce the load on the server somewhat. Lova
will keep you posted as we work on a fix, apologies for the inconvenience
in the meantime.

Regards

Tim

-- 
--

Tim Sutton
Kartoza Co-Founder
Visit http://kartoza.com to find out about open source:
 * Desktop GIS programming services
 * Geospatial web development
* GIS Training
* Consulting Services
Tim is a member of the QGIS Project Steering Committee
---
___
QGIS-Developer mailing list
QGIS-Developer@lists.osgeo.org
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer