()
| 106 | |
| 107 | /** |
| 108 | * Per-IP rate limit. Storage is in-memory by default and Valkey-backed |
| 109 | * when the cache provider is set to Valkey (see |
| 110 | * `buildRateLimitContext`). |
| 111 | * |
| 112 | * In BoringStack's default deployment, Traefik also rate-limits at the |
| 113 | * edge (see `infra/compose/compose/docker-compose.production-labels.yml`). |
| 114 | * This app-level limit is the second line of defence. |
| 115 | */ |
| 116 | export const buildRateLimit = () => { |
| 117 | const context = buildRateLimitContext("general"); |
| 118 | const generator = buildKeyGenerator(); |
| 119 | |
| 120 | return rateLimit({ |
| 121 | max: env.RATE_LIMIT_MAX, |
no test coverage detected