Skip to content

add rate limiting across auth, user, staff, and order endpoints - #43

Merged
AkibDa merged 3 commits into
GreenPlateByCodeNewbies:mainfrom
AkibDa:main
Feb 3, 2026
Merged

AkibDa merged 3 commits into
GreenPlateByCodeNewbies:mainfrom
AkibDa:main

Conversation

@AkibDa

@AkibDa AkibDa commented Feb 3, 2026

Copy link
Copy Markdown
Member
  • Integrated SlowAPI middleware
  • Protected payment, cancel, and resale flows
  • Added cost-safe limits for AI and upload endpoints

Comment thread app/app.py Fixed
Comment thread app/app.py Fixed
Comment thread app/app.py
@app.post('/auth/verify-staff', tags=["auth"])
async def verify_staff_endpoint(credentials: HTTPAuthorizationCredentials = Security(security)):
@limiter.limit("5/minute")
async def verify_staff_endpoint(

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Missing function or method docstring Warning

Missing function or method docstring
Comment thread app/app.py
@app.post('/auth/verify-student', tags=["auth"])
async def verify_student_endpoint(credentials: HTTPAuthorizationCredentials = Security(security)):
@limiter.limit("5/minute")
async def verify_student_endpoint(

Check warning

Code scanning / Pylintpython3 (reported by Codacy)

Missing function or method docstring Warning

Missing function or method docstring
Comment thread app/app.py Fixed

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prospector (reported by Codacy) found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pylint (reported by Codacy) found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

Comment thread app/app.py
from .webhook import router as webhook_router

def rate_limit_key(request: Request):
auth_header = request.headers.get("authorization")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
def rate_limit_key(request: Request):
auth_header = request.headers.get("authorization")

if auth_header:

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
auth_header = request.headers.get("authorization")

if auth_header:
token_hash = hashlib.sha256(auth_header.encode()).hexdigest()

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
Comment thread app/app.py

if auth_header:
token_hash = hashlib.sha256(auth_header.encode()).hexdigest()
return f"user:{token_hash}"

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
Comment thread app/app.py
token_hash = hashlib.sha256(auth_header.encode()).hexdigest()
return f"user:{token_hash}"

forwarded = request.headers.get("x-forwarded-for")

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
return f"user:{token_hash}"

forwarded = request.headers.get("x-forwarded-for")
if forwarded:

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py

forwarded = request.headers.get("x-forwarded-for")
if forwarded:
return f"ip:{forwarded.split(',')[0].strip()}"

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 4 spaces, expected 8 Note

Bad indentation. Found 4 spaces, expected 8
Comment thread app/app.py
if forwarded:
return f"ip:{forwarded.split(',')[0].strip()}"

return f"ip:{request.client.host}"

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
from .webhook import router as webhook_router

def rate_limit_key(request: Request):
"""

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
def health_check(request: Request):
"""
Health check endpoint for monitoring service availability.
"""

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
"""
_ = request
return {
"status": "ok",

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
Comment thread app/app.py
_ = request
return {
"status": "ok",
"service": "greenplate-backend",

Check notice

Code scanning / Pylintpython3 (reported by Codacy)

Bad indentation. Found 2 spaces, expected 4 Note

Bad indentation. Found 2 spaces, expected 4
@AkibDa
AkibDa merged commit 475ff24 into GreenPlateByCodeNewbies:main Feb 3, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants