aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/middleware.py
blob: 3a2a5c33875411c60e3f9998fff211342155a496 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
"""
Hub middleware — rate limiting on auth endpoints.

Uses slowapi (Starlette-compatible, token bucket algorithm).
Limits applied to /v1/users/register and /v1/users/login
to mitigate credential stuffing and registration floods.
"""

from slowapi import Limiter

from meshbay_hub.api.netutil import client_ip

# Rate limiter instance — mounted on the FastAPI app in app.py.
# Keyed on client_ip, not slowapi's get_remote_address: behind Caddy every
# request's peer is loopback, so the peer address put the whole internet in one
# bucket — ten node sign-ins a minute, shared by every node there is.
limiter = Limiter(key_func=client_ip)