Statement
Form endpoints shall enforce rate limiting per client IP address, with configurable thresholds (default: 5 submissions per 15 minutes) and adapter-aware IP resolution supporting reverse proxy and CDN headers (X-Forwarded-For, CF-Connecting-IP, X-Real-IP).
Rationale
Rate limiting is the baseline spam/abuse defense layer before CAPTCHA. IP resolution must handle CDN/proxy environments. Delivered by WP-C8 (D-C8-05).
Topics
Owner: component-system
Applies To
- Forms & Submission DOC-00017