Implement rate limiting and enhance authentication flow
- Added rate limiting configuration for authentication endpoints, allowing customizable request limits via environment variables. - Updated authentication flow to utilize HttpRequest for cookie management, ensuring secure handling of refresh tokens. - Introduced a new endpoint to retrieve user subscription details. - Enhanced the handling of Telegram bot token validation to prevent errors with empty tokens. - Updated the application to serialize enums as strings for better documentation and compatibility with TypeScript. - Improved test coverage for new features and adjustments in command handlers.
This commit is contained in:
@@ -33,6 +33,10 @@ AdminSeed__TelegramUserIds=123456789
|
||||
# Квота конфигов для системной роли "user" (выдаётся при регистрации).
|
||||
Roles__DefaultUserMaxConfigs=3
|
||||
|
||||
# ── Rate limiting ────────────────────────────────────────────────────────
|
||||
# Лимит запросов/мин на auth-эндпоинты (login/register/refresh/telegram/subscription). По умолчанию 20.
|
||||
# RateLimiting__AuthPermitLimit=20
|
||||
|
||||
# ── Telegram-бот ──────────────────────────────────────────────────────────
|
||||
# Если BotToken пуст — бот не стартует, панель работает без него.
|
||||
Telegram__BotToken=
|
||||
|
||||
Reference in New Issue
Block a user