Implement rate limiting and enhance authentication flow
- Added rate limiting configuration for authentication endpoints, allowing customizable request limits via environment variables. - Updated authentication flow to utilize HttpRequest for cookie management, ensuring secure handling of refresh tokens. - Introduced a new endpoint to retrieve user subscription details. - Enhanced the handling of Telegram bot token validation to prevent errors with empty tokens. - Updated the application to serialize enums as strings for better documentation and compatibility with TypeScript. - Improved test coverage for new features and adjustments in command handlers.
This commit is contained in:
+7
-1
@@ -27,7 +27,10 @@ public sealed class PnvPanelWebApplicationFactory : WebApplicationFactory<Progra
|
||||
.WithPassword("pnvpanel")
|
||||
.Build();
|
||||
|
||||
public async Task InitializeAsync() => await _postgres.StartAsync();
|
||||
public async Task InitializeAsync()
|
||||
{
|
||||
await _postgres.StartAsync();
|
||||
}
|
||||
|
||||
async Task IAsyncLifetime.DisposeAsync()
|
||||
{
|
||||
@@ -48,6 +51,9 @@ public sealed class PnvPanelWebApplicationFactory : WebApplicationFactory<Progra
|
||||
["AdminSeed:Password"] = AdminPassword,
|
||||
// Пусто — TelegramBotHostedService при пустом токене не стартует (см. Api/Telegram/TelegramBotHostedService.cs).
|
||||
["Telegram:BotToken"] = "",
|
||||
// Весь collection делит один TestServer/host — все запросы идут от одного "клиента",
|
||||
// дефолтный лимит 20/мин быстро исчерпывается. Поднимаем для тестового окружения.
|
||||
["RateLimiting:AuthPermitLimit"] = "10000",
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user