feat: rate limit public routes; backfill v0.9.5 changelog for mobile audit
Sign-in/sign-up now throttle at 3 req/10s/IP via better-auth's built-in rate limiter; /r/ and /s/ share links throttle at 60 req/min/IP via proxy.ts using the existing Redis-backed limiter (Next 16's Proxy always runs Node.js, no Edge-runtime blocker after all). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -10,6 +10,14 @@ import { gravatarUrl } from "@/lib/gravatar";
|
||||
export const auth = betterAuth({
|
||||
trustedOrigins: [process.env["BETTER_AUTH_URL"] ?? "http://localhost:3000"],
|
||||
|
||||
// Explicit rather than relying on the isProduction default so dev/staging
|
||||
// are protected too. Sign-in/sign-up/change-password/change-email get a
|
||||
// strict built-in 3-req/10s-per-IP rule (better-auth's default special
|
||||
// rules) — everything else on /api/auth falls back to 100/10s.
|
||||
rateLimit: {
|
||||
enabled: true,
|
||||
},
|
||||
|
||||
database: drizzleAdapter(db, {
|
||||
provider: "pg",
|
||||
schema: { user: users, session: sessions, account: accounts, verification: verifications },
|
||||
|
||||
Reference in New Issue
Block a user