feat(security): harden anti-DDoS gate with scanner triage, tiered blocks and in-process global halt
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s
This commit is contained in:
1 parent
98a184953a
commit
fd4d0fa1cb
4 files changed
+142
-38
No files matched your search
+6
-3
@@ -2,7 +2,7 @@ import { NextResponse } from "next/server";
|
||||
import { getToken } from "next-auth/jwt";
|
||||
import { env } from "@/env";
|
||||
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
|
||||
import { ddosRejected, enforceDdosRateLimit } from "@/lib/ddos-guard";
|
||||
import { ddosReject, enforceDdosRateLimit } from "@/lib/ddos-guard";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
@@ -16,8 +16,11 @@ const SECURITY_HEADERS: Record<string, string> = {
|
||||
|
||||
export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
const decision = await enforceDdosRateLimit(req);
|
||||
if (decision.limited) {
|
||||
return ddosRejected(decision.retryAfterSeconds);
|
||||
if (decision.outcome === "suspect") {
|
||||
return ddosReject(403);
|
||||
}
|
||||
if (decision.outcome === "block") {
|
||||
return ddosReject(429, decision.retryAfterSeconds);
|
||||
}
|
||||
|
||||
const pathname = req.nextUrl.pathname;
|
||||
|
||||
Reference in new issue
Block a user