• feat: implement rate limiting across all API endpoints

    fabi released this 2026-04-02 19:03:59 +00:00 | 34 commits to main since this release

    Add sliding-window in-memory RateLimiter service (Arc<Mutex>)
    with per-IP and per-user-id limits on all public endpoint classes:

    • POST /api/v1/join: 5/min per IP
    • GET /api/v1/feed: configurable per IP (feed_rate_per_min, default 60)
    • POST /api/v1/upload: configurable per user (upload_rate_per_hour, default 10)
    • GET /api/v1/export/zip|html: configurable per IP (export_rate_per_day, default 3)
      Limits are hot-reloadable via the config table. All 429 responses use
      German error messages. Client IP is read from X-Forwarded-For (Caddy).

    Co-Authored-By: Claude Sonnet 4.6 noreply@anthropic.com

    Downloads