feat: add Retry-After header and countdown timer for rate limits
- Rate limiter returns retryAfterSec in response body + Retry-After header - Registration rate limits: 10 per 10min (was 15/hour) - Frontend surfaces retry timer in error messages Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
592841d7b1
commit
3c32f01aa7
@@ -131,7 +131,7 @@ authRouter.post('/login', rateLimit(60_000, 30), async (c) => {
|
||||
})
|
||||
|
||||
// Register a new bot with Nostr pubkey
|
||||
authRouter.post('/register', rateLimit(3600_000, 15), async (c) => {
|
||||
authRouter.post('/register', rateLimit(600_000, 10), async (c) => {
|
||||
const body = await c.req.json()
|
||||
const { pubkey, name, webhookUrl, archetype, profilePicUrl, customization: rawCustomization } = body
|
||||
|
||||
@@ -231,7 +231,7 @@ authRouter.post('/register', rateLimit(3600_000, 15), async (c) => {
|
||||
|
||||
|
||||
// Register a human player (no webhook required)
|
||||
authRouter.post('/register-human', rateLimit(3600_000, 15), async (c) => {
|
||||
authRouter.post('/register-human', rateLimit(600_000, 10), async (c) => {
|
||||
const body = await c.req.json()
|
||||
const { pubkey, name, profilePicUrl, avatarSeed } = body
|
||||
|
||||
|
||||
Reference in New Issue
Block a user