f2a12f9fed
v0.4 (Operator Tier — Cohort Dashboard + Auth + Postgres) milestone complete. Phases: ✓ P0 pre-execution (planning) → v0.1.6 ✓ P1 operator foundation (Postgres+auth+VC migration) → v0.1.7 ✓ P2 cohort dashboard + aggregation → v0.1.8 ✓ P3 final review + ship → v0.1.9 (= v0.4 milestone release) Requirements covered (8/8): REQ-MT-01 (Postgres store), REQ-MT-02 (aggregation pipeline), REQ-AUTH-01 (operator auth), REQ-DASH-01 (cohort dashboard), REQ-NFR-AUTH-01 (auth NFRs), REQ-NFR-MT-01 (Postgres-in-LXC), REQ-NFR-DASH-01 (k-anonymity ≥10), REQ-NFR-DASH-02 (freshness ≤24h) Grill MUSTs honored (6/6): G-008, G-011, G-027, G-031, G-038, G-041 Tests: 317 pytest pass, 36 skip (Postgres-requiring), 0 fail; 17/17 vitest pass Review: APPROVE_WITH_NOTES (6/6 personas, 0 P0, 8 P1+ carry-forward) Audit: HEALTHY (reconstruction PASS, 8/8 REQ, 6/6 grill) ---ci--- project: praxis phase: 3 milestone: v0.4 status: complete phase_role: final milestone_complete: true milestone_merged_to_main: true tag: v0.1.9 requirements: covered: [REQ-MT-01, REQ-MT-02, REQ-AUTH-01, REQ-DASH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01, REQ-NFR-DASH-01, REQ-NFR-DASH-02] partial: [] ---/ci---
34 lines
1.1 KiB
Python
34 lines
1.1 KiB
Python
"""Login rate limiting (TASK-03-03, D-041).
|
|
|
|
slowapi Limiter with an in-memory backend (single-instance — D-041).
|
|
5 login attempts per minute per client IP. On exceed → 429 + Retry-After.
|
|
|
|
R-AUTH-03 (in-memory counter lost on restart) is an accepted pilot risk
|
|
(RESEARCH-v0.4 §2.5) — a restart at most resets the counter, which slightly
|
|
widens the brute-force window but does not enable it (argon2id + 5/min is
|
|
still the binding control). A hand-rolled counter is the documented
|
|
fallback if slowapi is ever removed.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from slowapi import Limiter
|
|
from slowapi.util import get_remote_address
|
|
|
|
limiter = Limiter(key_func=get_remote_address, storage_uri="memory://")
|
|
|
|
|
|
def reset_login_rate_limit() -> None:
|
|
"""Clear the in-memory rate-limit counters (test helper + restart-safe)."""
|
|
try:
|
|
limiter.reset()
|
|
except Exception:
|
|
pass
|
|
|
|
|
|
def rate_limit_login():
|
|
"""Decorator factory: 5 login attempts per minute per IP (D-041)."""
|
|
return limiter.limit("5/minute")
|
|
|
|
|
|
__all__ = ["limiter", "rate_limit_login", "reset_login_rate_limit"] |