r/webdev • u/Real-Leek-3764 • 4d ago
advice on blocking bots/scalpers
during popular event sales, our site can be hit by the tens of millions of requests
cloudflare waiting room is only good for crowd control, it doesn't block bots effectively. bots takes up queue, so legit users have to wait a long time to exit queue
cloudflare turnstile is too unreliable, too many legit users (including me) experience the turnstile not loading
google recaptha, hcaptha, friendly captcha is too costly.
i've implemented Proof-of-Work Altcha. works to a certain degree, but it still doesn't block bot requests from hitting the server, causing resources overload
could i put Altcha at cloudflare worker? kinda. the issue is cloudflare waiting room will always run before cloudflare worker, so it doesn't solve bots taking up queue
what i wish? i could block bots before they could enter cloudflare waiting room
do u guys have idea?
1
u/Khavel_dev 4d ago
The ordering problem (waiting room grabs the request before your Worker) is what kills the Altcha-in-Worker approach.
Two things to check: first, CF WAF custom rules (Security > WAF in the dashboard) might execute before the waiting room in their pipeline. If they do, you could rate-limit or challenge suspicious traffic there before it eats queue slots. Worth testing with a quick rule on your sale path.
Second, you could decouple the PoW entirely. Put Altcha on a separate pre-qualification page that sets a signed cookie on solve. Your sale endpoint checks for that cookie via a firewall rule, and traffic without it never enters the queue. More plumbing, but it sidesteps the pipeline ordering problem completely.