mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 21:12:49 +08:00
feat(auth): rate-limit /login+/setup, per-user session cap, periodic /me poll
This commit is contained in:
1 parent
1a11489f2e
commit
a39fc25104
6 files changed
+161
-1
No files matched your search
@@ -0,0 +1,41 @@
|
||||
import { describe, it, expect, beforeEach } from "vitest";
|
||||
import express from "express";
|
||||
import request from "supertest";
|
||||
import { createRateLimit } from "./rateLimit.js";
|
||||
|
||||
describe("createRateLimit", () => {
|
||||
let app: express.Express;
|
||||
|
||||
beforeEach(() => {
|
||||
app = express();
|
||||
// capacity=3, refill=1/sec → first 3 succeed, then 429 until refill.
|
||||
app.use(createRateLimit({ capacity: 3, refillPerSec: 1 }));
|
||||
app.get("/", (_req, res) => res.json({ ok: true }));
|
||||
});
|
||||
|
||||
it("allows up to capacity bursts then rejects with 429", async () => {
|
||||
expect((await request(app).get("/")).status).toBe(200);
|
||||
expect((await request(app).get("/")).status).toBe(200);
|
||||
expect((await request(app).get("/")).status).toBe(200);
|
||||
const denied = await request(app).get("/");
|
||||
expect(denied.status).toBe(429);
|
||||
expect(denied.body).toEqual({ error: "rate limit exceeded" });
|
||||
expect(denied.headers["retry-after"]).toBeDefined();
|
||||
});
|
||||
|
||||
it("uses per-key buckets when keyFn is provided", async () => {
|
||||
const customApp = express();
|
||||
customApp.use(
|
||||
createRateLimit({
|
||||
capacity: 1,
|
||||
refillPerSec: 0.001,
|
||||
keyFn: (req) => req.get("x-user") ?? "anon",
|
||||
})
|
||||
);
|
||||
customApp.get("/", (_req, res) => res.json({ ok: true }));
|
||||
expect((await request(customApp).get("/").set("X-User", "alice")).status).toBe(200);
|
||||
expect((await request(customApp).get("/").set("X-User", "alice")).status).toBe(429);
|
||||
// Different user, separate bucket → still has a token.
|
||||
expect((await request(customApp).get("/").set("X-User", "bob")).status).toBe(200);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,63 @@
|
||||
import type { Request, Response, NextFunction, RequestHandler } from "express";
|
||||
|
||||
interface Bucket {
|
||||
tokens: number;
|
||||
lastRefillMs: number;
|
||||
}
|
||||
|
||||
interface RateLimitOptions {
|
||||
/** Bucket capacity (max burst). */
|
||||
capacity: number;
|
||||
/** Tokens refilled per second. */
|
||||
refillPerSec: number;
|
||||
/** Optional key function; defaults to req.ip. */
|
||||
keyFn?: (req: Request) => string;
|
||||
}
|
||||
|
||||
/**
|
||||
* In-memory token-bucket rate limiter.
|
||||
*
|
||||
* Each unique key (default: req.ip) gets its own bucket. Refills continuously
|
||||
* at `refillPerSec` up to `capacity`. Each request consumes 1 token; if no
|
||||
* token is available, returns 429 with Retry-After.
|
||||
*
|
||||
* Buckets evict themselves after 10 minutes of inactivity to bound memory.
|
||||
*/
|
||||
export function createRateLimit(options: RateLimitOptions): RequestHandler {
|
||||
const buckets = new Map<string, Bucket>();
|
||||
const EVICT_AFTER_MS = 10 * 60 * 1000;
|
||||
// Periodic eviction to bound memory under attack.
|
||||
const evict = setInterval(() => {
|
||||
const cutoff = Date.now() - EVICT_AFTER_MS;
|
||||
for (const [k, b] of buckets) {
|
||||
if (b.lastRefillMs < cutoff) buckets.delete(k);
|
||||
}
|
||||
}, 60_000);
|
||||
// Unref the timer so it doesn't keep the process alive in tests.
|
||||
if (typeof (evict as { unref?: () => void }).unref === "function") {
|
||||
(evict as { unref: () => void }).unref();
|
||||
}
|
||||
|
||||
const keyFn = options.keyFn ?? ((req) => req.ip ?? "unknown");
|
||||
|
||||
return function rateLimit(req: Request, res: Response, next: NextFunction): void {
|
||||
const key = keyFn(req);
|
||||
const now = Date.now();
|
||||
let b = buckets.get(key);
|
||||
if (!b) {
|
||||
b = { tokens: options.capacity, lastRefillMs: now };
|
||||
buckets.set(key, b);
|
||||
}
|
||||
const elapsedSec = (now - b.lastRefillMs) / 1000;
|
||||
b.tokens = Math.min(options.capacity, b.tokens + elapsedSec * options.refillPerSec);
|
||||
b.lastRefillMs = now;
|
||||
if (b.tokens < 1) {
|
||||
const waitSec = Math.ceil((1 - b.tokens) / options.refillPerSec);
|
||||
res.setHeader("Retry-After", String(waitSec));
|
||||
res.status(429).json({ error: "rate limit exceeded" });
|
||||
return;
|
||||
}
|
||||
b.tokens -= 1;
|
||||
next();
|
||||
};
|
||||
}
|
||||
Reference in new issue
Block a user