267e80e2ec
- Refactor server initialization to separate concerns and improve error handling. - Implement centralized environment validation using Zod. - Introduce database, Redis, and queue lifecycle management. - Add health check endpoints for liveness and readiness. - Enhance error handling middleware for better response structure. - Implement rate limiting for API endpoints. - Add request ID middleware for traceability. - Create Sequelize CLI configuration and baseline migration for schema management. - Establish CI workflow with Gitea for testing and syntax checks. - Document foundational changes and migration strategy in PHASE_0_FOUNDATION_STABILIZATION.md. - Add Docker Compose configuration for local development and testing. - Implement unit and integration tests for critical functionality.
22 lines
723 B
JavaScript
22 lines
723 B
JavaScript
const { rateLimit } = require("express-rate-limit");
|
|
|
|
const response = { success: false, error: { code: "RATE_LIMITED", message: "Too many requests" } };
|
|
|
|
const generalApiLimiter = rateLimit({
|
|
windowMs: Number(process.env.API_RATE_LIMIT_WINDOW_MS) || 15 * 60 * 1000,
|
|
limit: Number(process.env.API_RATE_LIMIT_MAX) || 300,
|
|
standardHeaders: "draft-8",
|
|
legacyHeaders: false,
|
|
message: response,
|
|
});
|
|
|
|
const sensitiveLimiter = rateLimit({
|
|
windowMs: Number(process.env.SENSITIVE_RATE_LIMIT_WINDOW_MS) || 15 * 60 * 1000,
|
|
limit: Number(process.env.SENSITIVE_RATE_LIMIT_MAX) || 20,
|
|
standardHeaders: "draft-8",
|
|
legacyHeaders: false,
|
|
message: response,
|
|
});
|
|
|
|
module.exports = { generalApiLimiter, sensitiveLimiter };
|