

Can’t edit the post (Thanks Cloudflare! /s) but additional info:
- I truncated the log excerpts in the post. The user agent string in these requests isn’t shown here, but it is blank in the actual logs.
- This is for Lemmy admins only. It might apply to others in some form, but this seems to be specifically exploiting a Lemmy API endpoint
- My Nginx solution may have room for improvement; I was just trying to block that behavior without breaking comments in posts and move on with my day. Suggestions for improvement are welcome.








Unfortunately, there’s many many reasons that could be the case. I’m just putting this out there since it’s easy to check for and mitigate against.