From cd66254281e8d6000e6d465e7bd17dec1ff7594e Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Tue, 29 Sep 2026 15:55:50 +0200 Subject: [PATCH] =?UTF-8?q?fixup!=20=F0=9F=94=92=EF=B8=8F(backend)=20throt?= =?UTF-8?q?tle=20meeting=20link=20generation?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/backend/core/api/throttling.py | 13 ++++++++++++- src/backend/core/api/viewsets.py | 10 ++-------- 2 files changed, 14 insertions(+), 9 deletions(-) diff --git a/src/backend/core/api/throttling.py b/src/backend/core/api/throttling.py index dc416e3b..be2102b1 100644 --- a/src/backend/core/api/throttling.py +++ b/src/backend/core/api/throttling.py @@ -21,10 +21,21 @@ class MonitoredUserRateThrottle(MonitoredThrottleMixin, UserRateThrottle): class RoomCreationUserRateThrottle(MonitoredUserRateThrottle): - """Throttle room creation per authenticated user.""" + """Throttle room creation per authenticated user. + + Can be declared at the viewset level: every action other than "create" + is left unthrottled, so the same class can be reused on any viewset + exposing a room creation endpoint. + """ scope = "room_creation" + def get_cache_key(self, request, view): + """Throttle only room creations.""" + if getattr(view, "action", None) != "create": + return None + return super().get_cache_key(request, view) + class RequestEntryAuthenticatedUserRateThrottle(MonitoredUserRateThrottle): """Throttle authenticated user requesting room entry""" diff --git a/src/backend/core/api/viewsets.py b/src/backend/core/api/viewsets.py index 409c2dfe..48d74f03 100644 --- a/src/backend/core/api/viewsets.py +++ b/src/backend/core/api/viewsets.py @@ -1,5 +1,5 @@ """API endpoints""" -# pylint: disable=too-many-lines, too-many-public-methods +# pylint: disable=too-many-lines import uuid from datetime import timedelta @@ -180,13 +180,7 @@ class RoomViewSet( permission_classes = [permissions.RoomPermissions] queryset = models.Room.objects.all() serializer_class = serializers.RoomSerializer - - def get_throttles(self): - """Apply the room creation limit without affecting other room actions.""" - throttles = super().get_throttles() - if self.action == "create": - return [*throttles, throttling.RoomCreationUserRateThrottle()] - return throttles + throttle_classes = [throttling.RoomCreationUserRateThrottle] def get_object(self): """Allow getting a room by its slug."""