mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-10 03:27:59 +00:00
fix(server): rate-limit /api/analyze and /api/embed endpoints (#1328) (#1339)
Some checks are pending
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Release Candidate / Check if release candidate should run (push) Waiting to run
Release Candidate / ci (push) Blocked by required conditions
Release Candidate / Publish release candidate to npm (push) Blocked by required conditions
Release Candidate / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
Some checks are pending
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Release Candidate / Check if release candidate should run (push) Waiting to run
Release Candidate / ci (push) Blocked by required conditions
Release Candidate / Publish release candidate to npm (push) Blocked by required conditions
Release Candidate / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
This commit is contained in:
parent
3732fa1e21
commit
f10135649e
2 changed files with 10 additions and 2 deletions
|
|
@ -1348,7 +1348,7 @@ export const createServer = async (port: number, host: string = '127.0.0.1') =>
|
|||
// ── Analyze API ──────────────────────────────────────────────────────
|
||||
|
||||
// POST /api/analyze — start a new analysis job
|
||||
app.post('/api/analyze', async (req, res) => {
|
||||
app.post('/api/analyze', createRouteLimiter({ limit: 10 }), async (req, res) => {
|
||||
try {
|
||||
const { url: repoUrl, path: repoLocalPath, force, embeddings, dropEmbeddings } = req.body;
|
||||
|
||||
|
|
@ -1615,7 +1615,7 @@ export const createServer = async (port: number, host: string = '127.0.0.1') =>
|
|||
const embedJobManager = new JobManager();
|
||||
|
||||
// POST /api/embed — trigger server-side embedding generation
|
||||
app.post('/api/embed', async (req, res) => {
|
||||
app.post('/api/embed', createRouteLimiter({ limit: 20 }), async (req, res) => {
|
||||
try {
|
||||
const entry = await resolveRepo(requestedRepo(req));
|
||||
if (!entry) {
|
||||
|
|
|
|||
|
|
@ -230,6 +230,14 @@ describe('production routes — rate-limit middleware wiring', () => {
|
|||
expect(apiSource).toMatch(/app\.delete\('\/api\/repo',\s*createRouteLimiter\(/);
|
||||
});
|
||||
|
||||
it('POST /api/analyze is wired with createRouteLimiter', () => {
|
||||
expect(apiSource).toMatch(/app\.post\('\/api\/analyze',\s*createRouteLimiter\(/);
|
||||
});
|
||||
|
||||
it('POST /api/embed is wired with createRouteLimiter', () => {
|
||||
expect(apiSource).toMatch(/app\.post\('\/api\/embed',\s*createRouteLimiter\(/);
|
||||
});
|
||||
|
||||
it('SPA fallback is wired with createRouteLimiter', () => {
|
||||
expect(apiSource).toMatch(/app\.get\(SPA_FALLBACK_REGEX,\s*createRouteLimiter\(/);
|
||||
});
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue