Merge pull request #2221 from omnivore-app/fix/rate-limit

Change rate limiting rules
This commit is contained in:
Jackson Harper 2023-05-22 18:45:45 +08:00 committed by GitHub
commit 8451b8f84f
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -101,14 +101,15 @@ export const createApp = (): {
if (!env.dev.isLocal) {
const apiLimiter = rateLimit({
windowMs: 60 * 1000, // 1 minute
max: async (req) => {
// 50 RPM for an authenticated request, 5 for a non-authenticated request
const token = await getClaimsByToken(
// eslint-disable-next-line @typescript-eslint/no-unsafe-member-access
req.header('authorization') ?? req.cookies['auth']
)
return token ? 50 : 10
},
max: 100,
// async (req) => {
// // 100 RPM for an authenticated request, 5 for a non-authenticated request
// // const token = await getClaimsByToken(
// // // eslint-disable-next-line @typescript-eslint/no-unsafe-member-access
// // req.header('authorization') ?? req.cookies['auth']
// // )
// return 100 // token ? 100 : 10
// },
standardHeaders: true, // Return rate limit info in the `RateLimit-*` headers
legacyHeaders: false, // Disable the `X-RateLimit-*` headers
keyGenerator: (req) => {