00e39a3f85
Phase 1 complete — Operator Foundation: - Postgres 16 in Docker-in-LXC (asyncpg pool, 5-table schema, PgStore, migrations) - Operator auth (argon2id, signed stateless cookies, slowapi 5/min rate limit) - VC issuer key migration SQLite→Postgres (archive-before-active, R-VC-MIG-01) - Operator bootstrap CLI (create-operator.py, idempotent) - Backup cron script + G-008 restore drill - Graceful degradation (server starts without Postgres) - 272 tests pass, 33 skip (Postgres-requiring), 0 fail ---ci--- project: praxis phase: 1 milestone: v0.4 status: complete requirements: covered: [REQ-MT-01, REQ-AUTH-01, REQ-NFR-AUTH-01, REQ-NFR-MT-01, REQ-MT-02] partial: [] ---/ci---
34 lines
1.1 KiB
Python
34 lines
1.1 KiB
Python
"""Login rate limiting (TASK-03-03, D-041).
|
|
|
|
slowapi Limiter with an in-memory backend (single-instance — D-041).
|
|
5 login attempts per minute per client IP. On exceed → 429 + Retry-After.
|
|
|
|
R-AUTH-03 (in-memory counter lost on restart) is an accepted pilot risk
|
|
(RESEARCH-v0.4 §2.5) — a restart at most resets the counter, which slightly
|
|
widens the brute-force window but does not enable it (argon2id + 5/min is
|
|
still the binding control). A hand-rolled counter is the documented
|
|
fallback if slowapi is ever removed.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from slowapi import Limiter
|
|
from slowapi.util import get_remote_address
|
|
|
|
limiter = Limiter(key_func=get_remote_address, storage_uri="memory://")
|
|
|
|
|
|
def reset_login_rate_limit() -> None:
|
|
"""Clear the in-memory rate-limit counters (test helper + restart-safe)."""
|
|
try:
|
|
limiter.reset()
|
|
except Exception:
|
|
pass
|
|
|
|
|
|
def rate_limit_login():
|
|
"""Decorator factory: 5 login attempts per minute per IP (D-041)."""
|
|
return limiter.limit("5/minute")
|
|
|
|
|
|
__all__ = ["limiter", "rate_limit_login", "reset_login_rate_limit"] |