Files
webhooker/internal/middleware/ratelimit.go
sneak 8362ce9ee0
All checks were successful
check / check (push) Successful in 2m40s
Rate-limit the password change endpoint (#65)
The password change POST verifies the current password, making it
a password-based authentication endpoint that REPO_POLICIES.md
requires rate limiting on. Extract the login limiter's POST-only
per-IP pattern into a shared postRateLimit helper and apply the
same 5-per-minute limit to POST /user/{username}/password.
2026-08-07 16:29:43 +00:00

3.0 KiB