From 44ce5f2aa992c811bab59161509af7378a54914a Mon Sep 17 00:00:00 2001 From: Chris Troutner Date: Wed, 24 Feb 2021 14:14:36 -0800 Subject: [PATCH] fix(rate limits): Testing recursive rate limits --- package-lock.json | 14 +++++++------- package.json | 2 +- src/middleware/route-ratelimit.js | 13 ++++++++----- 3 files changed, 16 insertions(+), 13 deletions(-) diff --git a/package-lock.json b/package-lock.json index e91760c..7c8c776 100644 --- a/package-lock.json +++ b/package-lock.json @@ -8,7 +8,7 @@ "version": "1.16.0", "license": "MIT", "dependencies": { - "@psf/bch-js": "^4.15.2", + "@psf/bch-js": "^4.15.3", "apidoc": "^0.26.0", "axios": "^0.21.1", "bitcore-lib-cash": "^8.23.1", @@ -458,9 +458,9 @@ } }, "node_modules/@psf/bch-js": { - "version": "4.15.2", - "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.2.tgz", - "integrity": "sha512-ZJi6JdF2z/WJ02+G3Xs0V8GZUEe8HJuZqH5VEa7aq1dwZpWithq5rirZHNhWj5IfUwv3VQH6nYFObPo6Op6orA==", + "version": "4.15.3", + "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.3.tgz", + "integrity": "sha512-J5Jk1Y7oTmTs6kCX83hxY10kp5FZd0KI4bFGiZ8qJX+V1hqFsS57+Byd4qIa/+cK+PEyTifCMnCkfKVXLS8tHw==", "dependencies": { "@psf/bip21": "^2.0.1", "@psf/bip32-utils": "^0.13.1", @@ -18627,9 +18627,9 @@ } }, "@psf/bch-js": { - "version": "4.15.2", - "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.2.tgz", - "integrity": "sha512-ZJi6JdF2z/WJ02+G3Xs0V8GZUEe8HJuZqH5VEa7aq1dwZpWithq5rirZHNhWj5IfUwv3VQH6nYFObPo6Op6orA==", + "version": "4.15.3", + "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.3.tgz", + "integrity": "sha512-J5Jk1Y7oTmTs6kCX83hxY10kp5FZd0KI4bFGiZ8qJX+V1hqFsS57+Byd4qIa/+cK+PEyTifCMnCkfKVXLS8tHw==", "requires": { "@psf/bip21": "^2.0.1", "@psf/bip32-utils": "^0.13.1", diff --git a/package.json b/package.json index 36a1997..2136c84 100644 --- a/package.json +++ b/package.json @@ -29,7 +29,7 @@ "node": ">=10.15.1" }, "dependencies": { - "@psf/bch-js": "^4.15.2", + "@psf/bch-js": "^4.15.3", "apidoc": "^0.26.0", "axios": "^0.21.1", "bitcore-lib-cash": "^8.23.1", diff --git a/src/middleware/route-ratelimit.js b/src/middleware/route-ratelimit.js index d46ba98..beefa88 100644 --- a/src/middleware/route-ratelimit.js +++ b/src/middleware/route-ratelimit.js @@ -129,9 +129,17 @@ class RateLimits { const resource = _this.getResource(req.url) wlogger.debug(`resource: ${resource}`) + // Key will be the JWT ID if it exists, otherwise the IP address of the caller. let key = userId || req.ip res.locals.key = key // Feedback for tests. + // For internal calls that make a lot of internal calls, like + // hydrateUtxoDetails(), the origin of the caller will be passed in + // via the POST body. + if (req.body && req.body.ip) { + key = req.body.ip + } + // const pointsToConsume = userId ? 1 : 30 decoded.resource = resource let pointsToConsume = _this.calcPoints(decoded) @@ -147,11 +155,6 @@ class RateLimits { wlogger.info(`origin: ${origin}`) - const bodyOrigin = req.body.origin - if (bodyOrigin) { - console.log(`bodyOrigin: ${bodyOrigin}`) - } - // If the request originates from one of the approved wallet apps, then // apply paid-access rate limits. // console.log(`origin: ${JSON.stringify(origin, null, 2)}`)