2025-03-21 14:14:45 -04:00
|
|
|
const Keyv = require('keyv');
|
2024-06-07 21:06:47 +02:00
|
|
|
const rateLimit = require('express-rate-limit');
|
2025-03-21 14:14:45 -04:00
|
|
|
const { RedisStore } = require('rate-limit-redis');
|
2024-06-07 21:06:47 +02:00
|
|
|
const { ViolationTypes } = require('librechat-data-provider');
|
2025-03-21 14:14:45 -04:00
|
|
|
const { removePorts, isEnabled } = require('~/server/utils');
|
|
|
|
const keyvRedis = require('~/cache/keyvRedis');
|
2024-06-07 21:06:47 +02:00
|
|
|
const { logViolation } = require('~/cache');
|
2025-03-21 14:14:45 -04:00
|
|
|
const { logger } = require('~/config');
|
2024-06-07 21:06:47 +02:00
|
|
|
|
|
|
|
const {
|
|
|
|
VERIFY_EMAIL_WINDOW = 2,
|
|
|
|
VERIFY_EMAIL_MAX = 2,
|
|
|
|
VERIFY_EMAIL_VIOLATION_SCORE: score,
|
|
|
|
} = process.env;
|
|
|
|
const windowMs = VERIFY_EMAIL_WINDOW * 60 * 1000;
|
|
|
|
const max = VERIFY_EMAIL_MAX;
|
|
|
|
const windowInMinutes = windowMs / 60000;
|
|
|
|
const message = `Too many attempts, please try again after ${windowInMinutes} minute(s)`;
|
|
|
|
|
|
|
|
const handler = async (req, res) => {
|
|
|
|
const type = ViolationTypes.VERIFY_EMAIL_LIMIT;
|
|
|
|
const errorMessage = {
|
|
|
|
type,
|
|
|
|
max,
|
|
|
|
windowInMinutes,
|
|
|
|
};
|
|
|
|
|
|
|
|
await logViolation(req, res, type, errorMessage, score);
|
|
|
|
return res.status(429).json({ message });
|
|
|
|
};
|
|
|
|
|
2025-03-21 14:14:45 -04:00
|
|
|
const limiterOptions = {
|
2024-06-07 21:06:47 +02:00
|
|
|
windowMs,
|
|
|
|
max,
|
|
|
|
handler,
|
|
|
|
keyGenerator: removePorts,
|
2025-03-21 14:14:45 -04:00
|
|
|
};
|
|
|
|
|
|
|
|
if (isEnabled(process.env.USE_REDIS)) {
|
|
|
|
logger.debug('Using Redis for verify email rate limiter.');
|
|
|
|
const keyv = new Keyv({ store: keyvRedis });
|
|
|
|
const client = keyv.opts.store.redis;
|
|
|
|
const sendCommand = (...args) => client.call(...args);
|
|
|
|
const store = new RedisStore({
|
|
|
|
sendCommand,
|
|
|
|
prefix: 'verify_email_limiter:',
|
|
|
|
});
|
|
|
|
limiterOptions.store = store;
|
|
|
|
}
|
|
|
|
|
|
|
|
const verifyEmailLimiter = rateLimit(limiterOptions);
|
2024-06-07 21:06:47 +02:00
|
|
|
|
|
|
|
module.exports = verifyEmailLimiter;
|