Skip to content

Commit 013ef0a

Browse files
committed
added rate limiter middleware
1 parent 1fe5450 commit 013ef0a

File tree

10 files changed

+48
-54
lines changed

10 files changed

+48
-54
lines changed

src/app.d.ts

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
import { ApiClient } from '$lib/server/api';
22
import type { User } from 'lucia';
3-
import {parseApiResponse} from '$lib/utils/api'
3+
import { parseApiResponse } from '$lib/utils/api'
4+
import type { Security } from '$lib/utils/security';
45

56
// See https://kit.svelte.dev/docs/types#app
67
// for information about these interfaces
@@ -13,17 +14,17 @@ declare global {
1314
getAuthedUser: () => Promise<Returned<User> | null>;
1415
getAuthedUserOrThrow: () => Promise<Returned<User>>;
1516
}
16-
17+
1718
// interface PageData {}
1819
// interface PageState {}
1920
// interface Platform {}
2021
namespace Superforms {
21-
type Message = {
22-
type: 'error' | 'success',
23-
text: string
24-
}
25-
}
22+
type Message = {
23+
type: 'error' | 'success',
24+
text: string
25+
}
26+
}
2627
}
2728
}
2829

29-
export {};
30+
export { };

src/hooks.server.ts

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,6 @@ const apiClient: Handle = async ({ event, resolve }) => {
1515
}
1616
});
1717

18-
1918
/* ----------------------------- Auth functions ----------------------------- */
2019
async function getAuthedUser() {
2120
const { data } = await api.iam.user.$get().then(parseApiResponse)

src/lib/server/api/controllers/iam.controller.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,13 @@ import { IamService } from '../services/iam.service';
55
import { signInEmailDto } from '../../../dtos/signin-email.dto';
66
import { setCookie } from 'hono/cookie';
77
import { LuciaProvider } from '../providers/lucia.provider';
8-
import { requireAuth } from '../middleware/require-auth.middleware';
98
import { updateEmailDto } from '../../../dtos/update-email.dto';
109
import { verifyEmailDto } from '../../../dtos/verify-email.dto';
1110
import { Hono } from 'hono';
1211
import type { HonoTypes } from '../types';
1312
import type { Controller } from '../interfaces/controller.interface';
1413
import { limiter } from '../middleware/rate-limiter.middlware';
14+
import { requireAuth } from '../middleware/auth.middleware';
1515

1616
/* -------------------------------------------------------------------------- */
1717
/* Controller */

src/lib/server/api/middleware/auth-session.middleware.ts renamed to src/lib/server/api/middleware/auth.middleware.ts

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ import { createMiddleware } from 'hono/factory';
33
import type { HonoTypes } from '../types';
44
import { lucia } from '../infrastructure/auth/lucia';
55
import { verifyRequestOrigin } from 'lucia';
6+
import type { Session, User } from 'lucia';
7+
import { Unauthorized } from '../common/errors';
68

79
export const verifyOrigin: MiddlewareHandler<HonoTypes> = createMiddleware(async (c, next) => {
810
if (c.req.method === "GET") {
@@ -35,3 +37,14 @@ export const validateAuthSession: MiddlewareHandler<HonoTypes> = createMiddlewar
3537
c.set("user", user);
3638
return next();
3739
})
40+
41+
export const requireAuth: MiddlewareHandler<{
42+
Variables: {
43+
session: Session;
44+
user: User;
45+
};
46+
}> = createMiddleware(async (c, next) => {
47+
const user = c.var.user;
48+
if (!user) throw Unauthorized('You must be logged in to access this resource');
49+
return next();
50+
});

src/lib/server/api/middleware/rate-limiter.middlware.ts

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,18 +5,16 @@ import type { HonoTypes } from "../types";
55

66
const client = new RedisClient()
77

8-
type LimiterProps = {
8+
export function limiter({ limit, minutes, key = "" }: {
99
limit: number;
1010
minutes: number;
1111
key?: string;
12-
}
13-
14-
export function limiter({limit, minutes, key = ""}: LimiterProps) {
12+
}) {
1513
return rateLimiter({
1614
windowMs: minutes * 60 * 1000, // every x minutes
1715
limit, // Limit each IP to 100 requests per `window` (here, per 15 minutes).
1816
standardHeaders: "draft-6", // draft-6: `RateLimit-*` headers; draft-7: combined `RateLimit` header
19-
keyGenerator: (c) => {
17+
keyGenerator: (c) => {
2018
const vars = c.var as HonoTypes['Variables'];
2119
const clientKey = vars.user?.id || c.req.header("x-forwarded-for");
2220
const pathKey = key || c.req.routePath;

src/lib/server/api/middleware/require-auth.middleware.ts

Lines changed: 0 additions & 15 deletions
This file was deleted.

src/lib/server/api/services/iam.service.ts

Lines changed: 6 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ export class IamService {
3333
@inject(TokensService) private tokensService: TokensService,
3434
@inject(MailerService) private mailerService: MailerService,
3535
@inject(LuciaProvider) private lucia: LuciaProvider
36-
) {}
36+
) { }
3737

3838
async registerEmail(data: RegisterEmailDto) {
3939
const existingUser = await this.usersRepository.findOneByEmail(data.email);
@@ -48,16 +48,10 @@ export class IamService {
4848

4949
async signinEmail(data: SignInEmailDto) {
5050
const user = await this.usersRepository.findOneByEmail(data.email);
51-
52-
if (!user) {
53-
throw BadRequest('Bad credentials');
54-
}
51+
if (!user) throw BadRequest('Bad credentials');
5552

5653
const isValidToken = await this.tokensService.validateToken(user.id, data.token);
57-
58-
if (!isValidToken) {
59-
throw BadRequest('Bad credentials');
60-
}
54+
if (!isValidToken) throw BadRequest('Bad credentials');
6155

6256
// if this is a new unverified user, send a welcome email and update the user
6357
if (!user.verified) {
@@ -73,17 +67,11 @@ export class IamService {
7367

7468
async verifyEmail(userId: string, token: string) {
7569
const user = await this.usersRepository.findOneById(userId);
76-
77-
if (!user) {
78-
throw BadRequest('User not found');
79-
}
70+
if (!user) throw BadRequest('User not found');
8071

8172
const validToken = await this.tokensService.validateToken(user.id, token);
82-
83-
if (!validToken) {
84-
throw BadRequest('Invalid token');
85-
}
86-
73+
if (!validToken) throw BadRequest('Invalid token');
74+
8775
await this.usersRepository.update(user.id, { email: validToken.email });
8876
}
8977

src/routes/(app)/+layout.svelte

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,14 @@
33
import Menu from 'lucide-svelte/icons/menu';
44
import Package2 from 'lucide-svelte/icons/package-2';
55
import Search from 'lucide-svelte/icons/search';
6-
76
import { Button } from '$lib/components/ui/button/index.js';
8-
import * as Card from '$lib/components/ui/card/index.js';
9-
import { Checkbox } from '$lib/components/ui/checkbox/index.js';
107
import * as DropdownMenu from '$lib/components/ui/dropdown-menu/index.js';
118
import { Input } from '$lib/components/ui/input/index.js';
129
import * as Sheet from '$lib/components/ui/sheet/index.js';
1310
import { cn } from '$lib/utils/ui';
1411
import HouseIcon from 'lucide-svelte/icons/house';
1512
import { page } from '$app/stores';
13+
import { enhance } from '$app/forms';
1614
1715
let { children } = $props();
1816
@@ -98,7 +96,11 @@
9896
<DropdownMenu.Content align="end">
9997
<DropdownMenu.Item href="/settings">Settings</DropdownMenu.Item>
10098
<DropdownMenu.Separator />
101-
<DropdownMenu.Item>Logout</DropdownMenu.Item>
99+
<DropdownMenu.Item>
100+
<form action="/?/logout" method="POST" use:enhance class="w-full">
101+
<button class="w-full text-start cursor-default" type="submit">Logout</button>
102+
</form></DropdownMenu.Item
103+
>
102104
</DropdownMenu.Content>
103105
</DropdownMenu.Root>
104106
</div>

src/routes/(app)/+page.server.ts

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,11 @@ export const load = async ({ locals }) => {
22
const user = await locals.getAuthedUser();
33
return { user: user };
44
};
5+
6+
7+
export const actions = {
8+
logout: async ({ locals }) => {
9+
console.log("Logging out")
10+
await locals.api.iam.logout.$post()
11+
}
12+
}

src/routes/(app)/settings/account/+page.server.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ import { verifyEmailDto } from "$lib/dtos/verify-email.dto.js";
33
import { fail, setError, superValidate } from "sveltekit-superforms";
44
import { zod } from "sveltekit-superforms/adapters";
55

6-
export let load = async ({ locals }) => {
7-
const authedUser = await locals.getAuthedUserOrThrow();
6+
export let load = async (event) => {
7+
const authedUser = await event.locals.getAuthedUserOrThrow()
88

99
return {
1010
authedUser,

0 commit comments

Comments
 (0)