Change rate limiting rules

This commit is contained in:
Jackson Harper 2023-05-19 18:05:57 +08:00
parent 6122993e2a
commit f671b3625c

View file

@ -102,12 +102,12 @@ export const createApp = (): {
const apiLimiter = rateLimit({
windowMs: 60 * 1000, // 1 minute
max: async (req) => {
// 50 RPM for an authenticated request, 5 for a non-authenticated request
const token = await getClaimsByToken(
// eslint-disable-next-line @typescript-eslint/no-unsafe-member-access
req.header('authorization') ?? req.cookies['auth']
)
return token ? 50 : 10
// 100 RPM for an authenticated request, 5 for a non-authenticated request
// const token = await getClaimsByToken(
// // eslint-disable-next-line @typescript-eslint/no-unsafe-member-access
// req.header('authorization') ?? req.cookies['auth']
// )
return 100 // token ? 100 : 10
},
standardHeaders: true, // Return rate limit info in the `RateLimit-*` headers
legacyHeaders: false, // Disable the `X-RateLimit-*` headers