feat(api): add API rate limiting and abuse protection - #4
Conversation
|
@hrishu802 Reviewed the complete PR and the current implementation. The rate-limiting implementation is well structured, with Redis support, in-memory fallback, per-route policies, headers, and good test coverage. A few things need to be addressed before merge: CI issue — please fix the CI bug: The current GitHub Actions run is failing during the dependency-installation step, before type-checking, linting, build, and tests can even run. This appears to be an issue with the CI workflow/configuration, so please investigate and correct the CI bug first, then verify that the complete pipeline runs successfully. |
|
The CI lockfile issue has been fixed in dc52859. The new workflow run is currently awaiting maintainer approval before it can execute. |
vedant21-ctr
left a comment
There was a problem hiding this comment.
resolveRoutePolicy() still uses broad startsWith() matching, so paths like /api/v1/eventsSomething can get the events policy. Please make the prefix matching boundary-aware.
method is passed into resolveRoutePolicy() but isn’t actually used, so the current implementation/comment is slightly misleading.
maxMemoryKeys is exposed in RateLimitPluginOptions but the store is always created with the default 10000, so that option currently has no effect.
Please add a couple of negative/boundary tests for route matching.
Once the workflow gets maintainer approval, please confirm the full CI pipeline passes rather than relying only on the local 118/118 result.
The authenticated-user keying looks fine with the current preValidation → preHandler hook order.
dc52859 to
a86478d
Compare
|
Thanks for the review! I've addressed the requested changes:
The PR now shows no conflicts with the base branch. The GitHub Actions workflow is currently awaiting maintainer approval, so I'll wait for the CI run to complete. |
Summary
Validation