Merge ngit external-access PR 79ca68c1 into combined UAT candidate
Preserve current maintenance/session guards, Firewall UI and existing catalogs. Retain scoped guest access, publishing journeys and local Blossom integration. Normalize Blossom/router memory units to supported quadlet suffixes. Validation: 108 dashboard tests, 10 gateway policy tests, strict source catalog check. Integrated isolated backend qualification remains required before main.
This commit is contained in:
@@ -94,6 +94,15 @@ impl EndpointRateLimiter {
|
||||
limits.insert("identity.create".to_string(), (10, 300));
|
||||
limits.insert("identity.import-nostr".to_string(), (5, 300));
|
||||
limits.insert("identity.issue-credential".to_string(), (20, 300));
|
||||
// Explicit publishing actions can allocate credentials or perform
|
||||
// bounded network I/O. Saving/previewing never invokes these actions.
|
||||
limits.insert("publishing.gateway-configure".to_string(), (5, 60));
|
||||
limits.insert("publishing.gateway-app-route".to_string(), (10, 60));
|
||||
limits.insert("publishing.gateway-route".to_string(), (10, 60));
|
||||
limits.insert("publishing.access-create".to_string(), (10, 60));
|
||||
limits.insert("publishing.verify-https".to_string(), (10, 60));
|
||||
limits.insert("publishing.blossom-store".to_string(), (10, 60));
|
||||
limits.insert("publishing.generate".to_string(), (5, 300));
|
||||
// Backup operations (resource-intensive)
|
||||
limits.insert("backup.create".to_string(), (10, 600));
|
||||
limits.insert("backup.restore".to_string(), (5, 600));
|
||||
|
||||
Reference in New Issue
Block a user