feat(security): add rate limiting to public POST routes
CI / check (push) Successful in 2m48s
CI / deploy (push) Successful in 20s
CI / publish-container (push) Successful in 1m31s

Add rateLimit protection to /api/paypal/create, /api/paypal/capture, /api/tokens, /api/radio/shouts, and /api/articles/[slug]/comment to prevent abuse and spamming.
This commit is contained in:
openhands committed 2026-09-13 13:30:29 +02:00
1 parent 1caef76f82
commit ec742a3f72
5 files changed
+31

No files matched your search

@@ -10,6 +10,7 @@ import { eq } from "drizzle-orm";
import { apiError, apiJson } from "@/lib/api";
import { bearerUserId } from "@/lib/api-auth";
import { db, WebsiteArticleComments, WebsiteArticles } from "@/lib/db";
import { rateLimit } from "@/lib/rate-limit";
export async function POST(
req: Request,
@@ -18,6 +19,10 @@ export async function POST(
const uid = await bearerUserId(req);
if (!uid) return apiError("Unauthorized", 401);
if (!(await rateLimit(`article-comment:${uid}`, 10, 60_000)).ok) {
return apiError("Too many comments. Please wait a minute.", 429);
}
const { slug } = await params;
const body = (await req.json().catch(() => ({}))) as { comment?: unknown };
+8
View File
@@ -6,6 +6,7 @@ import { sessionUserId } from "@/lib/auth/session-user";
import { db, WebsitePaypalTransactions } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
import { logger } from "@/lib/logger";
import { rateLimit } from "@/lib/rate-limit";
import { logServerError } from "@/lib/server-log";
import {
type CaptureResult,
@@ -50,6 +51,13 @@ export async function POST(req: Request): Promise<Response> {
return NextResponse.json({ error: "Invalid session." }, { status: 401 });
}
if (!(await rateLimit(`paypal-capture:${userId}`, 5, 60_000)).ok) {
return NextResponse.json(
{ error: "Too many capture requests. Please wait a minute." },
{ status: 429 },
);
}
if (!isPayPalConfigured()) {
return NextResponse.json(
{
+8
View File
@@ -5,6 +5,7 @@ import { sessionUserId } from "@/lib/auth/session-user";
import { db, WebsitePaypalTransactions } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
import { logger } from "@/lib/logger";
import { rateLimit } from "@/lib/rate-limit";
import {
createOrder,
creditsPerUnit,
@@ -36,6 +37,13 @@ export async function POST(req: Request): Promise<Response> {
return NextResponse.json({ error: "Invalid session." }, { status: 401 });
}
if (!(await rateLimit(`paypal-create:${userId}`, 5, 60_000)).ok) {
return NextResponse.json(
{ error: "Too many top-up requests. Please wait a minute." },
{ status: 429 },
);
}
// Fail fast (and clearly) when the sandbox/live keys aren't set.
if (!isPayPalConfigured()) {
return NextResponse.json(
+5
View File
@@ -2,6 +2,7 @@ import { desc, inArray } from "drizzle-orm";
import { apiError, apiJson } from "@/lib/api";
import { bearerUserId } from "@/lib/api-auth";
import { db, RadioShouts, User } from "@/lib/db";
import { rateLimit } from "@/lib/rate-limit";
import { apiCacheKey, redisCache } from "@/lib/redis-cache";
// Latest 50 radio shouts with their author's username/look resolved. Mirrors the
@@ -71,6 +72,10 @@ export async function POST(req: Request) {
const uid = await bearerUserId(req);
if (!uid) return apiError("Unauthorized", 401);
if (!(await rateLimit(`radio-shout:${uid}`, 10, 60_000)).ok) {
return apiError("Too many shouts. Please wait a minute.", 429);
}
const body = (await req.json().catch(() => ({}))) as { message?: unknown };
const message = typeof body.message === "string" ? body.message.trim() : "";
+5
View File
@@ -9,6 +9,7 @@ import { apiError, apiJson } from "@/lib/api";
import { issueToken } from "@/lib/api-auth";
import { auth } from "@/lib/auth";
import { sessionUserId } from "@/lib/auth/session-user";
import { rateLimit } from "@/lib/rate-limit";
export async function POST(req: Request) {
const session = await auth();
@@ -17,6 +18,10 @@ export async function POST(req: Request) {
return apiError("Unauthorized", 401);
}
if (!(await rateLimit(`tokens-issue:${id}`, 5, 60_000)).ok) {
return apiError("Too many token requests. Please wait a minute.", 429);
}
const body = (await req.json().catch(() => ({}))) as { name?: unknown };
const rawName = typeof body.name === "string" ? body.name.trim() : "";
const name = rawName ? rawName.slice(0, 100) : "api";