aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/middleware.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/middleware.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/middleware.py13
1 files changed, 13 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/middleware.py b/packages/meshbay-hub/src/meshbay_hub/api/middleware.py
new file mode 100644
index 0000000..bed7b54
--- /dev/null
+++ b/packages/meshbay-hub/src/meshbay_hub/api/middleware.py
@@ -0,0 +1,13 @@
+"""
+Hub middleware — rate limiting on auth endpoints.
+
+Uses slowapi (Starlette-compatible, token bucket algorithm).
+Limits applied to /v1/users/register and /v1/users/login
+to mitigate credential stuffing and registration floods.
+"""
+
+from slowapi import Limiter
+from slowapi.util import get_remote_address
+
+# Rate limiter instance — mounted on the FastAPI app in app.py
+limiter = Limiter(key_func=get_remote_address)