blob: 3a2a5c33875411c60e3f9998fff211342155a496 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
"""
Hub middleware — rate limiting on auth endpoints.
Uses slowapi (Starlette-compatible, token bucket algorithm).
Limits applied to /v1/users/register and /v1/users/login
to mitigate credential stuffing and registration floods.
"""
from slowapi import Limiter
from meshbay_hub.api.netutil import client_ip
# Rate limiter instance — mounted on the FastAPI app in app.py.
# Keyed on client_ip, not slowapi's get_remote_address: behind Caddy every
# request's peer is loopback, so the peer address put the whole internet in one
# bucket — ten node sign-ins a minute, shared by every node there is.
limiter = Limiter(key_func=client_ip)
|