feat: 敏感操作增加IP维度限流
- RateLimiter 新增 AllowSensitive 方法(1分钟5次,超限封禁5分钟) - 新增 SensitiveRateLimit Gin 中间件 - 改密(PUT /api/settings/password)增加限流保护 - 注销(POST /api/settings/delete-account)增加限流保护 - 签到(POST /api/level/checkin)增加限流保护
This commit is contained in:
@ -32,3 +32,8 @@ func (rl *RateLimiter) AllowAccount(email string) RateLimitResult {
|
||||
func (rl *RateLimiter) AllowIP(ip string) RateLimitResult {
|
||||
return rl.try(rl.ipFailures, ip, ipWindow, ipBlockDur, ipMaxFails, false)
|
||||
}
|
||||
|
||||
// AllowSensitive 敏感操作限流(改密/注销/签到),基于 IP,1 分钟最多 5 次,超限封禁 5 分钟。
|
||||
func (rl *RateLimiter) AllowSensitive(ip string) RateLimitResult {
|
||||
return rl.try(rl.ipFailures, "sensitive:"+ip, sensitiveWindow, sensitiveBlockDur, sensitiveMaxRequests, false)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user