Files
EpicNext-Cms/src/lib/rate-limit.ts
T
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00

73 lines
2.3 KiB
TypeScript

import { headers } from "next/headers";
/**
* Tiny in-process fixed-window rate limiter for abuse-prone server actions
* (register, password reset, login). It's per-node (not shared across
* instances) — fine for a single-server retro hotel; swap for Redis if you
* ever scale out. Keys are typically `${action}:${ip}`.
*
* Periodic cleanup runs every 5 minutes to keep the map bounded.
*/
type Bucket = { count: number; resetAt: number };
const buckets = new Map<string, Bucket>();
export interface RateLimitResult {
ok: boolean;
/** Seconds until the window resets (0 when allowed). */
retryAfter: number;
}
let lastCleanup = Date.now();
const CLEANUP_INTERVAL_MS = 300_000; // 5 min
const MAX_BUCKETS = 10_000;
function cleanup(): void {
const now = Date.now();
if (now - lastCleanup < CLEANUP_INTERVAL_MS) return;
lastCleanup = now;
if (buckets.size <= MAX_BUCKETS) {
// Quick eviction of completely expired entries
for (const [k, b] of buckets) if (now >= b.resetAt) buckets.delete(k);
} else {
// Aggressive: clear all expired, then delete oldest 20% if still too large
for (const [k, b] of buckets) if (now >= b.resetAt) buckets.delete(k);
if (buckets.size > MAX_BUCKETS) {
const sorted = [...buckets.entries()].sort((a, b) => a[1].resetAt - b[1].resetAt);
const toRemove = Math.floor(sorted.length * 0.2);
for (let i = 0; i < toRemove; i++) buckets.delete(sorted[i][0]);
}
}
}
export function rateLimit(key: string, limit: number, windowMs: number): RateLimitResult {
const now = Date.now();
cleanup();
const bucket = buckets.get(key);
if (!bucket || now >= bucket.resetAt) {
buckets.set(key, { count: 1, resetAt: now + windowMs });
return { ok: true, retryAfter: 0 };
}
if (bucket.count >= limit) {
return { ok: false, retryAfter: Math.max(1, Math.ceil((bucket.resetAt - now) / 1000)) };
}
bucket.count += 1;
return { ok: true, retryAfter: 0 };
}
/** Best-effort client IP from the proxy headers our edge proxy forwards. */
export async function clientIp(): Promise<string> {
try {
const h = await headers();
return (
h.get("x-real-client-ip") ??
h.get("cf-connecting-ip") ??
h.get("x-forwarded-for")?.split(",")[0]?.trim() ??
h.get("x-real-ip") ??
"0.0.0.0"
);
} catch {
return "0.0.0.0";
}
}