Fix Critical Security Issue: Implement rate limiting on API endpoints

Added comprehensive rate limiting to prevent abuse and DoS attacks:

Configuration (config/settings/base.py):
- Anon rate: 100 requests/hour for anonymous users
- User rate: 1000 requests/hour for authenticated users
- Login rate: 10 attempts/hour (prevents brute force)
- Register rate: 5 attempts/hour (prevents account spam)
- Sync rate: 100 requests/hour (prevents sync flooding)

Custom throttle classes (users/throttles.py):
- LoginRateThrottle: Strict limit for login endpoint
- RegisterRateThrottle: Strict limit for registration endpoint
- SyncRateThrottle: Moderate limit for sync endpoint

Applied throttling to sensitive endpoints:
- users.views.RegisterAPIView: 5/hour
- users.views.TokenObtainPairView: 10/hour
- sync.views.sync: 100/hour

All other API endpoints use default throttles (anon: 100/hour, user: 1000/hour).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
Keith Smith
2025-12-22 22:36:54 -07:00
co-authored by Claude Sonnet 4.5
parent b57321e1e4
commit deabe6ab3d
4 changed files with 49 additions and 1 deletions
+11
View File
@@ -123,6 +123,17 @@ REST_FRAMEWORK = {
], ],
'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.PageNumberPagination', 'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.PageNumberPagination',
'PAGE_SIZE': 50, 'PAGE_SIZE': 50,
'DEFAULT_THROTTLE_CLASSES': [
'rest_framework.throttling.AnonRateThrottle',
'rest_framework.throttling.UserRateThrottle',
],
'DEFAULT_THROTTLE_RATES': {
'anon': '100/hour', # Anonymous users: 100 requests per hour
'user': '1000/hour', # Authenticated users: 1000 requests per hour
'login': '10/hour', # Login attempts: 10 per hour
'register': '5/hour', # Registration attempts: 5 per hour
'sync': '100/hour', # Sync endpoint: 100 per hour
},
} }
# JWT Settings # JWT Settings
+3 -1
View File
@@ -10,7 +10,7 @@ from datetime import datetime
from django.utils import timezone from django.utils import timezone
from django.utils.dateparse import parse_datetime from django.utils.dateparse import parse_datetime
from rest_framework import status from rest_framework import status
from rest_framework.decorators import api_view, permission_classes from rest_framework.decorators import api_view, permission_classes, throttle_classes
from rest_framework.permissions import IsAuthenticated from rest_framework.permissions import IsAuthenticated
from rest_framework.response import Response from rest_framework.response import Response
@@ -25,12 +25,14 @@ from tasks.serializers import (
) )
from .models import SyncLog, SyncConflict from .models import SyncLog, SyncConflict
from .serializers import SyncConflictSerializer from .serializers import SyncConflictSerializer
from users.throttles import SyncRateThrottle
logger = logging.getLogger(__name__) logger = logging.getLogger(__name__)
@api_view(['POST']) @api_view(['POST'])
@permission_classes([IsAuthenticated]) @permission_classes([IsAuthenticated])
@throttle_classes([SyncRateThrottle])
def sync(request): def sync(request):
""" """
Main sync endpoint. Main sync endpoint.
+32
View File
@@ -0,0 +1,32 @@
"""
Custom throttle classes for user-related endpoints.
"""
from rest_framework.throttling import AnonRateThrottle, UserRateThrottle
class LoginRateThrottle(AnonRateThrottle):
"""
Rate limit for login attempts.
Stricter than general anonymous rate to prevent brute force attacks.
"""
scope = 'login'
class RegisterRateThrottle(AnonRateThrottle):
"""
Rate limit for registration attempts.
Prevents automated account creation and abuse.
"""
scope = 'register'
class SyncRateThrottle(UserRateThrottle):
"""
Rate limit for sync endpoint.
Prevents excessive sync requests that could overload the server.
"""
scope = 'sync'
+3
View File
@@ -21,6 +21,7 @@ from .serializers import (
DeviceTokenSerializer, DeviceTokenSerializer,
) )
from .models import DeviceToken, EmailVerificationToken from .models import DeviceToken, EmailVerificationToken
from .throttles import LoginRateThrottle, RegisterRateThrottle
User = get_user_model() User = get_user_model()
@@ -35,6 +36,7 @@ class RegisterAPIView(generics.CreateAPIView):
queryset = User.objects.all() queryset = User.objects.all()
serializer_class = UserRegistrationSerializer serializer_class = UserRegistrationSerializer
permission_classes = [permissions.AllowAny] permission_classes = [permissions.AllowAny]
throttle_classes = [RegisterRateThrottle]
def create(self, request, *args, **kwargs): def create(self, request, *args, **kwargs):
serializer = self.get_serializer(data=request.data) serializer = self.get_serializer(data=request.data)
@@ -225,6 +227,7 @@ class TokenObtainPairView(BaseTokenObtainPairView):
"""Custom JWT token view using our custom serializer.""" """Custom JWT token view using our custom serializer."""
serializer_class = CustomTokenObtainPairSerializer serializer_class = CustomTokenObtainPairSerializer
throttle_classes = [LoginRateThrottle]
# ============================================================================= # =============================================================================