All checks were successful
Deploy to Production / Build and Deploy (push) Successful in 1m35s
MCP Server: - Fix validateApiKey: O(1) direct lookup by shortId instead of loading all keys - Add trashedAt:null filter to ALL note queries (trashed notes leaked in results) - Compact JSON output (~40% smaller responses) - Bounded session cache (Map with MAX_SESSIONS=500) to prevent memory leaks - PostgreSQL connection pooling (connection_limit=10) - Rewrite all 22 tool descriptions in clear English - Fix /sse fallback to proper 307 redirect memento-note Performance: - loading=lazy on all note images - Split notebooksRefreshKey from global refreshKey (note CRUD no longer re-fetches notebooks) - Remove searchKey from trash count deps (no re-fetch on every keystroke) - Server-side notebookId filter in getAllNotes() (biggest win) - Skip collaborator fetch for non-shared notes (eliminates N+1 API calls) - next/dynamic for MarkdownContent + 4 modals (code-split remark/rehype/KaTeX) - Memoize DOMPurify sanitize with useMemo Security: - XSS: DOMPurify sanitize in note-card and note-history-modal - Auth anti-enumeration: uniform errors in auth.ts - CRON_SECRET mandatory on cron endpoints - Rate limiting on login (5 attempts/min per email) - Centralized API auth helpers (requireAuth/requireAdmin) - randomize-labels changed GET→POST - Removed debug endpoints (/api/debug/config, /api/debug/test-chat) Cleanup: - Removed dead code: .backup-keep, settings-backup, fix-*.js, debug-theme, fix-labels route - Removed sensitive console.error in auth.ts - Ollama fetchWithTimeout (30s/60s AbortController) - i18n: full Arabic translation, Farsi missing keys - Masonry drag-and-drop fix (localOrderMap, cross-section block) - Sidebar notebook tooltip on truncation
30 lines
727 B
TypeScript
30 lines
727 B
TypeScript
const attempts = new Map<string, { count: number; resetAt: number }>()
|
|
|
|
const WINDOW_MS = 60_000
|
|
const MAX_ATTEMPTS = 5
|
|
|
|
export function rateLimit(key: string): { allowed: boolean; retryAfterMs: number } {
|
|
const now = Date.now()
|
|
const entry = attempts.get(key)
|
|
|
|
if (!entry || now > entry.resetAt) {
|
|
attempts.set(key, { count: 1, resetAt: now + WINDOW_MS })
|
|
return { allowed: true, retryAfterMs: 0 }
|
|
}
|
|
|
|
entry.count++
|
|
|
|
if (entry.count > MAX_ATTEMPTS) {
|
|
return { allowed: false, retryAfterMs: entry.resetAt - now }
|
|
}
|
|
|
|
return { allowed: true, retryAfterMs: 0 }
|
|
}
|
|
|
|
setInterval(() => {
|
|
const now = Date.now()
|
|
for (const [k, v] of attempts) {
|
|
if (now > v.resetAt) attempts.delete(k)
|
|
}
|
|
}, 60_000)
|