Skip to content

[S4.1-11] Add Abuse Controls (Rate Limiting for Auth and Guess APIs) #21

@humanauction

Description

@humanauction

Labels: stage-4, security, backend
Depends on: S4.1-04, S4.1-06

Acceptance Criteria:

  • Login and guess endpoints are rate-limited.
  • 429 behavior is deterministic and tested.
  • Limits are configurable by environment.
  • Logging captures throttle events for ops visibility.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions