feat(security): add rate limiting to public POST routes
Add rateLimit protection to /api/paypal/create, /api/paypal/capture, /api/tokens, /api/radio/shouts, and /api/articles/[slug]/comment to prevent abuse and spamming.
This commit is contained in:
1 parent
1caef76f82
commit
ec742a3f72
5 files changed
+31
No files matched your search
@@ -2,6 +2,7 @@ import { desc, inArray } from "drizzle-orm";
|
||||
import { apiError, apiJson } from "@/lib/api";
|
||||
import { bearerUserId } from "@/lib/api-auth";
|
||||
import { db, RadioShouts, User } from "@/lib/db";
|
||||
import { rateLimit } from "@/lib/rate-limit";
|
||||
import { apiCacheKey, redisCache } from "@/lib/redis-cache";
|
||||
|
||||
// Latest 50 radio shouts with their author's username/look resolved. Mirrors the
|
||||
@@ -71,6 +72,10 @@ export async function POST(req: Request) {
|
||||
const uid = await bearerUserId(req);
|
||||
if (!uid) return apiError("Unauthorized", 401);
|
||||
|
||||
if (!(await rateLimit(`radio-shout:${uid}`, 10, 60_000)).ok) {
|
||||
return apiError("Too many shouts. Please wait a minute.", 429);
|
||||
}
|
||||
|
||||
const body = (await req.json().catch(() => ({}))) as { message?: unknown };
|
||||
const message = typeof body.message === "string" ? body.message.trim() : "";
|
||||
|
||||
|
||||
Reference in new issue
Block a user