perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests

- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008)
- Replace in-process rate limiter with Redis-backed implementation with in-memory fallback
- Add Redis caching layer for site settings with TTL invalidation (migration 0009)
- Add rate limiting to resetPassword to prevent token brute-force attacks
- Update all rateLimit callers to await the now-async function
- Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns
- Update radio contest/giveaway pages to display new fields
- Add tests for rate limiter (4 tests) and password-reset actions (3 tests)
- Add REDIS_URL environment variable (optional, falls back to in-memory)
This commit is contained in:
openhands committed 2026-07-08 12:49:24 +02:00
1 parent 43c0ba6614
commit 5c638cd6bc
25 files changed
+449 -63

No files matched your search

+2 -1
View File
@@ -43,6 +43,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
export const { handlers, signIn, signOut, auth } = NextAuth({
trustHost: true,
secret: process.env.AUTH_SECRET,
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
pages: { signIn: "/login" },
providers: [
@@ -58,7 +59,7 @@ export const { handlers, signIn, signOut, auth } = NextAuth({
if (!username || !password) return null;
// Throttle login attempts per IP (10 per 5 min) against credential stuffing.
if (!rateLimit(`login:${await clientIp()}`, 10, 5 * 60_000).ok) return null;
if (!(await rateLimit(`login:${await clientIp()}`, 10, 5 * 60_000)).ok) return null;
const user = await prisma.user.findUnique({ where: { username } });
if (!user) {