Internal
Public Access
Fix Critical Security Issue: Implement rate limiting on API endpoints
Added comprehensive rate limiting to prevent abuse and DoS attacks: Configuration (config/settings/base.py): - Anon rate: 100 requests/hour for anonymous users - User rate: 1000 requests/hour for authenticated users - Login rate: 10 attempts/hour (prevents brute force) - Register rate: 5 attempts/hour (prevents account spam) - Sync rate: 100 requests/hour (prevents sync flooding) Custom throttle classes (users/throttles.py): - LoginRateThrottle: Strict limit for login endpoint - RegisterRateThrottle: Strict limit for registration endpoint - SyncRateThrottle: Moderate limit for sync endpoint Applied throttling to sensitive endpoints: - users.views.RegisterAPIView: 5/hour - users.views.TokenObtainPairView: 10/hour - sync.views.sync: 100/hour All other API endpoints use default throttles (anon: 100/hour, user: 1000/hour). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.5
parent
b57321e1e4
commit
deabe6ab3d
@@ -123,6 +123,17 @@ REST_FRAMEWORK = {
|
|||||||
],
|
],
|
||||||
'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.PageNumberPagination',
|
'DEFAULT_PAGINATION_CLASS': 'rest_framework.pagination.PageNumberPagination',
|
||||||
'PAGE_SIZE': 50,
|
'PAGE_SIZE': 50,
|
||||||
|
'DEFAULT_THROTTLE_CLASSES': [
|
||||||
|
'rest_framework.throttling.AnonRateThrottle',
|
||||||
|
'rest_framework.throttling.UserRateThrottle',
|
||||||
|
],
|
||||||
|
'DEFAULT_THROTTLE_RATES': {
|
||||||
|
'anon': '100/hour', # Anonymous users: 100 requests per hour
|
||||||
|
'user': '1000/hour', # Authenticated users: 1000 requests per hour
|
||||||
|
'login': '10/hour', # Login attempts: 10 per hour
|
||||||
|
'register': '5/hour', # Registration attempts: 5 per hour
|
||||||
|
'sync': '100/hour', # Sync endpoint: 100 per hour
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
# JWT Settings
|
# JWT Settings
|
||||||
|
|||||||
+3
-1
@@ -10,7 +10,7 @@ from datetime import datetime
|
|||||||
from django.utils import timezone
|
from django.utils import timezone
|
||||||
from django.utils.dateparse import parse_datetime
|
from django.utils.dateparse import parse_datetime
|
||||||
from rest_framework import status
|
from rest_framework import status
|
||||||
from rest_framework.decorators import api_view, permission_classes
|
from rest_framework.decorators import api_view, permission_classes, throttle_classes
|
||||||
from rest_framework.permissions import IsAuthenticated
|
from rest_framework.permissions import IsAuthenticated
|
||||||
from rest_framework.response import Response
|
from rest_framework.response import Response
|
||||||
|
|
||||||
@@ -25,12 +25,14 @@ from tasks.serializers import (
|
|||||||
)
|
)
|
||||||
from .models import SyncLog, SyncConflict
|
from .models import SyncLog, SyncConflict
|
||||||
from .serializers import SyncConflictSerializer
|
from .serializers import SyncConflictSerializer
|
||||||
|
from users.throttles import SyncRateThrottle
|
||||||
|
|
||||||
logger = logging.getLogger(__name__)
|
logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
|
||||||
@api_view(['POST'])
|
@api_view(['POST'])
|
||||||
@permission_classes([IsAuthenticated])
|
@permission_classes([IsAuthenticated])
|
||||||
|
@throttle_classes([SyncRateThrottle])
|
||||||
def sync(request):
|
def sync(request):
|
||||||
"""
|
"""
|
||||||
Main sync endpoint.
|
Main sync endpoint.
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
"""
|
||||||
|
Custom throttle classes for user-related endpoints.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from rest_framework.throttling import AnonRateThrottle, UserRateThrottle
|
||||||
|
|
||||||
|
|
||||||
|
class LoginRateThrottle(AnonRateThrottle):
|
||||||
|
"""
|
||||||
|
Rate limit for login attempts.
|
||||||
|
|
||||||
|
Stricter than general anonymous rate to prevent brute force attacks.
|
||||||
|
"""
|
||||||
|
scope = 'login'
|
||||||
|
|
||||||
|
|
||||||
|
class RegisterRateThrottle(AnonRateThrottle):
|
||||||
|
"""
|
||||||
|
Rate limit for registration attempts.
|
||||||
|
|
||||||
|
Prevents automated account creation and abuse.
|
||||||
|
"""
|
||||||
|
scope = 'register'
|
||||||
|
|
||||||
|
|
||||||
|
class SyncRateThrottle(UserRateThrottle):
|
||||||
|
"""
|
||||||
|
Rate limit for sync endpoint.
|
||||||
|
|
||||||
|
Prevents excessive sync requests that could overload the server.
|
||||||
|
"""
|
||||||
|
scope = 'sync'
|
||||||
@@ -21,6 +21,7 @@ from .serializers import (
|
|||||||
DeviceTokenSerializer,
|
DeviceTokenSerializer,
|
||||||
)
|
)
|
||||||
from .models import DeviceToken, EmailVerificationToken
|
from .models import DeviceToken, EmailVerificationToken
|
||||||
|
from .throttles import LoginRateThrottle, RegisterRateThrottle
|
||||||
|
|
||||||
User = get_user_model()
|
User = get_user_model()
|
||||||
|
|
||||||
@@ -35,6 +36,7 @@ class RegisterAPIView(generics.CreateAPIView):
|
|||||||
queryset = User.objects.all()
|
queryset = User.objects.all()
|
||||||
serializer_class = UserRegistrationSerializer
|
serializer_class = UserRegistrationSerializer
|
||||||
permission_classes = [permissions.AllowAny]
|
permission_classes = [permissions.AllowAny]
|
||||||
|
throttle_classes = [RegisterRateThrottle]
|
||||||
|
|
||||||
def create(self, request, *args, **kwargs):
|
def create(self, request, *args, **kwargs):
|
||||||
serializer = self.get_serializer(data=request.data)
|
serializer = self.get_serializer(data=request.data)
|
||||||
@@ -225,6 +227,7 @@ class TokenObtainPairView(BaseTokenObtainPairView):
|
|||||||
"""Custom JWT token view using our custom serializer."""
|
"""Custom JWT token view using our custom serializer."""
|
||||||
|
|
||||||
serializer_class = CustomTokenObtainPairSerializer
|
serializer_class = CustomTokenObtainPairSerializer
|
||||||
|
throttle_classes = [LoginRateThrottle]
|
||||||
|
|
||||||
|
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
|
|||||||
Reference in New Issue
Block a user