import rateLimit from 'express-rate-limit' // Public auth endpoints get their own brute-force budget (see authLimiter) // and must not consume the shared API budget, otherwise a bad-token storm // can lock the owner out of logging back in. const PUBLIC_AUTH_PATHS = [ '/api/auth/login', '/api/auth/register', '/api/auth/forgotpassword', '/api/auth/resetpassword', ] // Shared budget for real API traffic. Counts failures too (cheap 401s, no DB // hit), but skips CORS preflights, the health probe, and the public auth // endpoints above so junk traffic and login attempts can't drain it. export const apiLimiter = rateLimit({ windowMs: 15 * 60 * 1000, // 15 minutes max: 300, skip: (req) => req.method === 'OPTIONS' || req.path === '/health' || PUBLIC_AUTH_PATHS.some((p) => req.path.startsWith(p)), }) // Strict budget for the login door only. Successful logins are free // (skipSuccessfulRequests), so normal use never notices it — only repeated // failed attempts burn budget. 429 here means "wrong password 20 times in // 15 minutes", never "the API was busy". export const authLimiter = rateLimit({ windowMs: 15 * 60 * 1000, // 15 minutes max: 20, skipSuccessfulRequests: true, message: { success: false, error: 'Too many login attempts, please try again later.', }, })