fixup! 🔒️(backend) throttle meeting link generation

This commit is contained in:
lebaudantoine
2026-09-29 15:55:50 +02:00
parent 352d9ada6a
commit cd66254281
2 changed files with 14 additions and 9 deletions
+12 -1
View File
@@ -21,10 +21,21 @@ class MonitoredUserRateThrottle(MonitoredThrottleMixin, UserRateThrottle):
class RoomCreationUserRateThrottle(MonitoredUserRateThrottle):
"""Throttle room creation per authenticated user."""
"""Throttle room creation per authenticated user.
Can be declared at the viewset level: every action other than "create"
is left unthrottled, so the same class can be reused on any viewset
exposing a room creation endpoint.
"""
scope = "room_creation"
def get_cache_key(self, request, view):
"""Throttle only room creations."""
if getattr(view, "action", None) != "create":
return None
return super().get_cache_key(request, view)
class RequestEntryAuthenticatedUserRateThrottle(MonitoredUserRateThrottle):
"""Throttle authenticated user requesting room entry"""
+2 -8
View File
@@ -1,5 +1,5 @@
"""API endpoints"""
# pylint: disable=too-many-lines, too-many-public-methods
# pylint: disable=too-many-lines
import uuid
from datetime import timedelta
@@ -180,13 +180,7 @@ class RoomViewSet(
permission_classes = [permissions.RoomPermissions]
queryset = models.Room.objects.all()
serializer_class = serializers.RoomSerializer
def get_throttles(self):
"""Apply the room creation limit without affecting other room actions."""
throttles = super().get_throttles()
if self.action == "create":
return [*throttles, throttling.RoomCreationUserRateThrottle()]
return throttles
throttle_classes = [throttling.RoomCreationUserRateThrottle]
def get_object(self):
"""Allow getting a room by its slug."""