perf: add bans.user_id index, Redis cache layer, rate-limit improvements, radio contest/giveaway columns, and tests
- Add DB index on bans.user_id to speed up per-request ban lookups (migration 0008) - Replace in-process rate limiter with Redis-backed implementation with in-memory fallback - Add Redis caching layer for site settings with TTL invalidation (migration 0009) - Add rate limiting to resetPassword to prevent token brute-force attacks - Update all rateLimit callers to await the now-async function - Flesh out RadioContests and RadioGiveaways models with title, description, prize, date, and winner columns - Update radio contest/giveaway pages to display new fields - Add tests for rate limiter (4 tests) and password-reset actions (3 tests) - Add REDIS_URL environment variable (optional, falls back to in-memory)
This commit is contained in:
1 parent
43c0ba6614
commit
5c638cd6bc
25 files changed
+449
-63
No files matched your search
@@ -0,0 +1,47 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
vi.mock("@/lib/redis", () => ({
|
||||
redis: null,
|
||||
}));
|
||||
|
||||
import { rateLimit } from "./rate-limit";
|
||||
|
||||
beforeEach(() => {
|
||||
vi.restoreAllMocks();
|
||||
});
|
||||
|
||||
describe("rateLimit (in-memory fallback)", () => {
|
||||
it("allows the first request", async () => {
|
||||
const res = await rateLimit("test:1", 3, 60_000);
|
||||
expect(res.ok).toBe(true);
|
||||
expect(res.retryAfter).toBe(0);
|
||||
});
|
||||
|
||||
it("allows up to the limit within a window", async () => {
|
||||
const key = `test:2:${Date.now()}`;
|
||||
expect((await rateLimit(key, 2, 60_000)).ok).toBe(true);
|
||||
expect((await rateLimit(key, 2, 60_000)).ok).toBe(true);
|
||||
const res = await rateLimit(key, 2, 60_000);
|
||||
expect(res.ok).toBe(false);
|
||||
expect(res.retryAfter).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it("resets after the window expires", async () => {
|
||||
const key = `test:3:${Date.now()}`;
|
||||
await rateLimit(key, 1, 50);
|
||||
const res1 = await rateLimit(key, 1, 50);
|
||||
expect(res1.ok).toBe(false);
|
||||
await new Promise((r) => setTimeout(r, 60));
|
||||
const res2 = await rateLimit(key, 1, 50);
|
||||
expect(res2.ok).toBe(true);
|
||||
});
|
||||
|
||||
it("uses separate keys independently", async () => {
|
||||
const a = await rateLimit("key-a", 1, 60_000);
|
||||
const b = await rateLimit("key-b", 1, 60_000);
|
||||
expect(a.ok).toBe(true);
|
||||
expect(b.ok).toBe(true);
|
||||
const a2 = await rateLimit("key-a", 1, 60_000);
|
||||
expect(a2.ok).toBe(false);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user