Should this be part of IdentityServer4? seems like something that would be best tackled by just using another middleware which has the configurability to throttle endpoint(s)
I agree - that's why this issue is called "discuss" ;)
I only think there are 2 places that might need this -- userinfo and introspection, and I think these possible caching considered here: https://github.com/IdentityServer/IdentityServer4/issues/253#issuecomment-252445187 will be sufficient in addressing any flooding issues.
The kind of throttling we were discussing would need to be done more inside IdSvr with more intelligence, so this issue will be the main one to satisfy this: https://github.com/IdentityServer/IdentityServer4/issues/253
This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Most helpful comment
Should this be part of IdentityServer4? seems like something that would be best tackled by just using another middleware which has the configurability to throttle endpoint(s)