feat(security): add Redis-backed app-layer anti-DDoS rate limiting to proxy
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m40s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m40s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
This commit is contained in:
1 parent
d8f2a21011
commit
98a184953a
5 files changed
+184
-8
No files matched your search
+23
-8
@@ -2,6 +2,7 @@ import { NextResponse } from "next/server";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
import { env } from "@/env";
|
||||
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
|
||||
import { ddosRejected, enforceDdosRateLimit } from "@/lib/ddos-guard";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
@@ -14,13 +15,25 @@ const SECURITY_HEADERS: Record<string, string> = {
|
||||
};
|
||||
|
||||
export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
const token = await getToken({
|
||||
req,
|
||||
secret: env.AUTH_SECRET,
|
||||
secureCookie: true,
|
||||
});
|
||||
const decision = await enforceDdosRateLimit(req);
|
||||
if (decision.limited) {
|
||||
return ddosRejected(decision.retryAfterSeconds);
|
||||
}
|
||||
|
||||
if (shouldRedirectAdminRequest(req.nextUrl.pathname, token)) {
|
||||
const pathname = req.nextUrl.pathname;
|
||||
|
||||
// Only /admin needs a real session token for the redirect guard; skipping
|
||||
// JWT decoding on every other request keeps the proxy cheap under load.
|
||||
const adminPath = pathname === "/admin" || pathname.startsWith("/admin/");
|
||||
const token = adminPath
|
||||
? await getToken({
|
||||
req,
|
||||
secret: env.AUTH_SECRET,
|
||||
secureCookie: true,
|
||||
})
|
||||
: null;
|
||||
|
||||
if (shouldRedirectAdminRequest(pathname, token)) {
|
||||
return NextResponse.redirect(new URL("/login", req.url));
|
||||
}
|
||||
|
||||
@@ -28,7 +41,7 @@ export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
const csp = buildContentSecurityPolicy(nonce);
|
||||
|
||||
const headers = new Headers(req.headers);
|
||||
headers.set("x-pathname", req.nextUrl.pathname);
|
||||
headers.set("x-pathname", pathname);
|
||||
headers.set("x-nonce", nonce);
|
||||
|
||||
// A client may supply this legacy derived header; no consumer should trust it.
|
||||
@@ -54,5 +67,7 @@ export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
};
|
||||
|
||||
export const config = {
|
||||
matcher: ["/((?!api|_next/static|_next/image|assets|favicon.ico).*)"],
|
||||
matcher: [
|
||||
"/((?!_next/static|_next/image|assets|favicon.ico|swf|nitro-assets|imaging).*)",
|
||||
],
|
||||
};
|
||||
Reference in new issue
Block a user