fix: CI workflow, password reset flow, health/limits in services, session refactor, dead mixin stub cleanup
This commit is contained in:
parent
45dd592c40
commit
f4e15b45c9
95 changed files with 899 additions and 185 deletions
|
|
@ -14,7 +14,7 @@ http-body-util = "0.1"
|
|||
tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "time"] }
|
||||
tower-http = { version = "0.7", features = ["cors", "trace", "fs"] }
|
||||
tracing = "0.1"
|
||||
tracing-subscriber = "0.3"
|
||||
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
||||
serde_json = "1"
|
||||
uuid = { version = "1", features = ["v4"] }
|
||||
reqwest = { version = "0.13", default-features = false, features = ["stream"] }
|
||||
|
|
|
|||
|
|
@ -15,7 +15,7 @@ use axum::{
|
|||
use config::Config;
|
||||
use identity::device::DeviceAuthenticator;
|
||||
use std::sync::Arc;
|
||||
use tower_http::{cors::CorsLayer, services::ServeDir};
|
||||
use tower_http::{cors::CorsLayer, services::ServeDir, trace::TraceLayer};
|
||||
|
||||
pub fn build_app(cfg: &Config, devices: Arc<dyn DeviceAuthenticator>) -> Router {
|
||||
let upstreams = Arc::new(proxy::forward::Upstreams::new(cfg).expect("valid upstream config"));
|
||||
|
|
@ -69,6 +69,9 @@ pub fn build_app(cfg: &Config, devices: Arc<dyn DeviceAuthenticator>) -> Router
|
|||
guard::reject_ambiguous_paths,
|
||||
))
|
||||
.layer(cors)
|
||||
// Outermost so every route (health, downloads, proxied API) is
|
||||
// traced; spans carry method/path/status for the fmt subscriber.
|
||||
.layer(TraceLayer::new_for_http())
|
||||
}
|
||||
|
||||
fn spawn_purger(limits: Arc<rate_limit::RateLimits>) {
|
||||
|
|
|
|||
|
|
@ -4,7 +4,12 @@ use std::sync::Arc;
|
|||
#[tokio::main]
|
||||
async fn main() -> anyhow::Result<()> {
|
||||
dotenvy::dotenv().ok();
|
||||
tracing_subscriber::fmt::init();
|
||||
tracing_subscriber::fmt()
|
||||
.with_env_filter(
|
||||
tracing_subscriber::EnvFilter::try_from_default_env()
|
||||
.unwrap_or_else(|_| tracing_subscriber::EnvFilter::new("info")),
|
||||
)
|
||||
.init();
|
||||
let cfg = gateway::config::Config::from_env()?;
|
||||
cfg.validate()?;
|
||||
let devices = Arc::new(GrpcDevices::connect_lazy(
|
||||
|
|
|
|||
|
|
@ -46,6 +46,20 @@ pub fn rules() -> Vec<Rule> {
|
|||
vec![
|
||||
rule(Method::POST, "/auth/login", Quota::per_minute(n(5)), Ip),
|
||||
rule(Method::POST, "/auth/register", Quota::per_hour(n(3)), Ip),
|
||||
// Same threat as register: each accepted request sends an email, so
|
||||
// the mailer must not be usable as a spam cannon.
|
||||
rule(
|
||||
Method::POST,
|
||||
"/auth/forgot-password",
|
||||
Quota::per_hour(n(3)),
|
||||
Ip,
|
||||
),
|
||||
rule(
|
||||
Method::POST,
|
||||
"/auth/reset-password",
|
||||
Quota::per_minute(n(10)),
|
||||
Ip,
|
||||
),
|
||||
rule(Method::POST, "/auth/refresh", Quota::per_minute(n(30)), Ip),
|
||||
rule(Method::POST, "/device/code", Quota::per_minute(n(10)), Ip),
|
||||
// The mod polls every 2–3 s for up to 10 min: 10/min would break linking.
|
||||
|
|
@ -61,7 +75,12 @@ pub fn rules() -> Vec<Rule> {
|
|||
rule(Method::POST, "/avatars", Quota::per_hour(n(5)), Account),
|
||||
rule(Method::GET, "/showcase*", Quota::per_minute(n(60)), Ip),
|
||||
// The mod syncs menu presence about 3 times a second while a menu is open.
|
||||
rule(Method::POST, "/presence/*", Quota::per_second(n(6)), Account),
|
||||
rule(
|
||||
Method::POST,
|
||||
"/presence/*",
|
||||
Quota::per_second(n(6)),
|
||||
Account,
|
||||
),
|
||||
]
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue