fix: prevent setup screen showing on rate limit and exclude status checks from auth rate limiting

- Login component now handles 429 rate limit responses correctly
- When rate limited, assume auth is configured and show login form
- /api/security/status endpoint excluded from strict auth rate limiting
- Status checks now use general API rate limit (500/min) instead of auth limit (10/min)
- Fixes issue where rapid logout/login could trigger rate limiting
- Fixes setup screen appearing incorrectly when rate limited
This commit is contained in:
Pulse Monitor
2025-08-17 07:08:42 +00:00
parent 445adaa340
commit 625fac99b5
2 changed files with 6 additions and 2 deletions
+2 -2
View File
@@ -763,8 +763,8 @@ func (r *Router) ServeHTTP(w http.ResponseWriter, req *http.Request) {
}
}
// Apply stricter rate limiting for auth endpoints
if strings.Contains(req.URL.Path, "/api/security/") || req.URL.Path == "/api/login" {
// Apply stricter rate limiting for auth endpoints (but not status checks)
if (strings.Contains(req.URL.Path, "/api/security/") && req.URL.Path != "/api/security/status") || req.URL.Path == "/api/login" {
clientIP := GetClientIP(req)
// Use auth limiter for security endpoints (10 per minute)
if !authLimiter.Allow(clientIP) {