feat(security): add rate limiting to public POST routes
CI / check (push) Successful in 2m48s
CI / deploy (push) Successful in 20s
CI / publish-container (push) Successful in 1m31s

Add rateLimit protection to /api/paypal/create, /api/paypal/capture, /api/tokens, /api/radio/shouts, and /api/articles/[slug]/comment to prevent abuse and spamming.
This commit is contained in:
openhands committed 2026-09-13 13:30:29 +02:00
1 parent 1caef76f82
commit ec742a3f72
5 files changed
+31

No files matched your search

+5
View File
@@ -2,6 +2,7 @@ import { desc, inArray } from "drizzle-orm";
import { apiError, apiJson } from "@/lib/api";
import { bearerUserId } from "@/lib/api-auth";
import { db, RadioShouts, User } from "@/lib/db";
import { rateLimit } from "@/lib/rate-limit";
import { apiCacheKey, redisCache } from "@/lib/redis-cache";
// Latest 50 radio shouts with their author's username/look resolved. Mirrors the
@@ -71,6 +72,10 @@ export async function POST(req: Request) {
const uid = await bearerUserId(req);
if (!uid) return apiError("Unauthorized", 401);
if (!(await rateLimit(`radio-shout:${uid}`, 10, 60_000)).ok) {
return apiError("Too many shouts. Please wait a minute.", 429);
}
const body = (await req.json().catch(() => ({}))) as { message?: unknown };
const message = typeof body.message === "string" ? body.message.trim() : "";