# Struggles with Stick-table string

**URL:** <https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156>\
**Category:** Help!\
**Created:** [April 3, 2026, 1:58pm UTC](https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156 "2026-04-03T13:58:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sybren](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@Sybren](https://discourse.haproxy.org/u/Sybren)\
**Post date:** [April 3, 2026, 1:58pm UTC](https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156/1 "2026-04-03T13:58:00Z")

</div>

Hello,

Im having a bit of an issue blocking based on a token. My intention is to allow a token specified in the url. To be allowed only once. (in the below example per hour)

It’s a http backend, my original config is quite long so for clearness decided to post the most relevant part.

```bash
backend be_remote from http_frontend

    default-server ssl verify none
    server remoteapp 192.168.36.18

    acl token_reuse sc1_inc_gpc1(be_remote) gt 0

    stick-table type string len 120 size 100k expire 1h store gpc0
    http-request track-sc1 url_param(token)

    http-request deny if { url_param(token),table_gpc1(be_remote) gt 1 }

```

My stick table gets filled just fine. (And I can likely get away with len 64), but after a day of trying almost everything…

table: be\_remote, type: string, size:102400, used:1

```auto
0x1815faaa4488: key=CBD4B86D34CA070BC6984DCE0FDFC41795D1ABFC199607650257EC3752A9E5C7 use=3 exp=3591138 shard=0 gpc0=0

```

This is a actual token, but they invalidate soon enough.  
The above works for a large part except it does not block requests, my intention is that a second or more http request containing the same token should be blocked.

for completeness we call this with  
`https://<url>/rdp/#/client/NwBjAG15c3Fs?token=CBD4B86D34CA070BC6984DCE0FDFC41795D1ABFC199607650257EC3752A9E5C7`

Now I’m thinking that the comparison is maybe to blame because we use a string, but I cant find any examples or similar configs. (plenty with ip src etc counters, but almost none with string).

Can someone tell me why this does not work? I figured perhaps it was an issue that the traffic was already flowing and thus it might not be blocked anymore, so I moved the deny logic to a http\_frontend, but same issue, hence my suspection of it being related to the data being stored as a key=value.

Hope someone can help me out

---

<div class="post-metadata">

**Author:** ![Sybren](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@Sybren](https://discourse.haproxy.org/u/Sybren)\
**Post date:** [April 9, 2026, 9:39am UTC](https://discourse.haproxy.org/t/struggles-with-stick-table-string/12156/2 "2026-04-09T09:39:50Z")

</div>

I’ve partially figured it out. The config does work, however it just blocks the websocket creation, the application used, swallows that and fails back to http only.

I did learn something new, and the idea I had will simply not work. Web applications is not my area of expertise, but I do have a new appreciation for web developers 🙂
