mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
fix(web): make the SSE streams' 200/min rate limit actually apply (#691)
app.py called limiter.limit("200 per minute")(stream_x) after the routes
were registered and discarded the result. flask-limiter 3.x enforces a
decorated limit in the wrapper limit() returns, and marks the original
function so the before_request middleware skips it, so the streams had
no limit at all -- not even the 1000/min default. Register the wrapper
as the view instead.
The new test (skipped without flask-limiter) reconnects to each stream
201 times and expects the last to get a 429; it fails on the old code.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -925,10 +925,14 @@ def stream_logs():
|
||||
# Each SSE stream is one long-lived request, so only a (re)connect counts
|
||||
# against a limit. The streams get their own 200 per minute, tighter than the
|
||||
# 1000 per minute default, which bounds a client stuck reconnecting.
|
||||
# flask-limiter enforces a decorated limit in the wrapper limit() returns, and
|
||||
# marks the original function exempt from the default, so the wrapper has to
|
||||
# replace the registered view: discarding it leaves the streams unlimited.
|
||||
if limiter:
|
||||
limiter.limit("200 per minute")(stream_stats)
|
||||
limiter.limit("200 per minute")(stream_display)
|
||||
limiter.limit("200 per minute")(stream_logs)
|
||||
for _endpoint in ('stream_stats', 'stream_display', 'stream_logs'):
|
||||
app.view_functions[_endpoint] = limiter.limit("200 per minute")(
|
||||
app.view_functions[_endpoint]
|
||||
)
|
||||
|
||||
@app.route('/favicon.ico')
|
||||
def favicon():
|
||||
|
||||
Reference in New Issue
Block a user