Skip to content

fix: add rate limiting to auth service endpoints#188

Open
jakebromberg wants to merge 2 commits intomainfrom
fix/12-auth-rate-limiting
Open

fix: add rate limiting to auth service endpoints#188
jakebromberg wants to merge 2 commits intomainfrom
fix/12-auth-rate-limiting

Conversation

@jakebromberg
Copy link
Member

Summary

  • Adds express-rate-limit middleware to the auth service (apps/auth/app.ts), limiting auth endpoints to 10 requests per 15-minute window per IP.
  • Login, password reset, and anonymous sign-in were previously unbounded, leaving them vulnerable to brute-force attacks.
  • Adds a unit test that verifies rate limiting configuration is present in the auth app source.

Test plan

  • Unit test tests/unit/auth/rate-limiting.test.ts passes (verifies express-rate-limit import, rateLimit() config, and middleware ordering before the auth handler)
  • Manual smoke test: hit /auth/sign-in/email more than 10 times in 15 minutes and confirm 429 response

Made with Cursor

The auth service had no rate limiting, leaving login, password reset,
and anonymous sign-in vulnerable to brute-force attacks.

Co-authored-by: Cursor <cursoragent@cursor.com>
@jakebromberg jakebromberg force-pushed the fix/12-auth-rate-limiting branch from 21f53fa to de98620 Compare February 27, 2026 05:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant