""" Hub middleware — rate limiting on auth endpoints. Uses slowapi (Starlette-compatible, token bucket algorithm). Limits applied to /v1/users/register and /v1/users/login to mitigate credential stuffing and registration floods. """ from slowapi import Limiter from meshbay_hub.api.netutil import client_ip # Rate limiter instance — mounted on the FastAPI app in app.py. # Keyed on client_ip, not slowapi's get_remote_address: behind Caddy every # request's peer is loopback, so the peer address put the whole internet in one # bucket — ten node sign-ins a minute, shared by every node there is. limiter = Limiter(key_func=client_ip)