mirror of
https://github.com/omnivore-app/omnivore.git
synced 2026-03-11 08:54:26 +00:00
Use auth token to identify client request in rate limiter
This commit is contained in:
parent
12472ce094
commit
c9ea622461
1 changed files with 9 additions and 1 deletions
|
|
@ -94,12 +94,20 @@ export const createApp = (): {
|
|||
app.use(json({ limit: '100mb' }))
|
||||
app.use(urlencoded({ limit: '100mb', extended: true }))
|
||||
|
||||
if (!env.dev.isLocal) {
|
||||
if (env.dev.isLocal) {
|
||||
const apiLimiter = rateLimit({
|
||||
windowMs: 60 * 1000, // 1 minute
|
||||
max: 50, // Limit each IP to 10 requests per `window` (here, per minute)
|
||||
standardHeaders: true, // Return rate limit info in the `RateLimit-*` headers
|
||||
legacyHeaders: false, // Disable the `X-RateLimit-*` headers
|
||||
keyGenerator: (req) => {
|
||||
return (
|
||||
req.header('authorization') ||
|
||||
// eslint-disable-next-line @typescript-eslint/no-unsafe-member-access
|
||||
(req.cookies['auth'] as string) ||
|
||||
req.ip
|
||||
)
|
||||
},
|
||||
})
|
||||
// Apply the rate limiting middleware to API calls only
|
||||
app.use('/api/', apiLimiter)
|
||||
|
|
|
|||
Loading…
Reference in a new issue