mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-01 06:58:43 +00:00
fixup! 🔒️(backend) throttle meeting link generation
This commit is contained in:
@@ -21,10 +21,21 @@ class MonitoredUserRateThrottle(MonitoredThrottleMixin, UserRateThrottle):
|
||||
|
||||
|
||||
class RoomCreationUserRateThrottle(MonitoredUserRateThrottle):
|
||||
"""Throttle room creation per authenticated user."""
|
||||
"""Throttle room creation per authenticated user.
|
||||
|
||||
Can be declared at the viewset level: every action other than "create"
|
||||
is left unthrottled, so the same class can be reused on any viewset
|
||||
exposing a room creation endpoint.
|
||||
"""
|
||||
|
||||
scope = "room_creation"
|
||||
|
||||
def get_cache_key(self, request, view):
|
||||
"""Throttle only room creations."""
|
||||
if getattr(view, "action", None) != "create":
|
||||
return None
|
||||
return super().get_cache_key(request, view)
|
||||
|
||||
|
||||
class RequestEntryAuthenticatedUserRateThrottle(MonitoredUserRateThrottle):
|
||||
"""Throttle authenticated user requesting room entry"""
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
"""API endpoints"""
|
||||
# pylint: disable=too-many-lines, too-many-public-methods
|
||||
# pylint: disable=too-many-lines
|
||||
|
||||
import uuid
|
||||
from datetime import timedelta
|
||||
@@ -180,13 +180,7 @@ class RoomViewSet(
|
||||
permission_classes = [permissions.RoomPermissions]
|
||||
queryset = models.Room.objects.all()
|
||||
serializer_class = serializers.RoomSerializer
|
||||
|
||||
def get_throttles(self):
|
||||
"""Apply the room creation limit without affecting other room actions."""
|
||||
throttles = super().get_throttles()
|
||||
if self.action == "create":
|
||||
return [*throttles, throttling.RoomCreationUserRateThrottle()]
|
||||
return throttles
|
||||
throttle_classes = [throttling.RoomCreationUserRateThrottle]
|
||||
|
||||
def get_object(self):
|
||||
"""Allow getting a room by its slug."""
|
||||
|
||||
Reference in New Issue
Block a user