Overview
Endpoints in src/profile-completeness/profile-completeness.controller.ts are sensitive (authentication, credential/secret handling, payment data, token redemption, or state-changing admin actions) and should be protected against brute-force and abuse with request throttling. Apply a rate-limit/throttler guard with limits appropriate to each endpoint.
Specifications
Features:
- Sensitive handlers are covered by a throttling guard.
- Limits are tuned per endpoint (stricter on auth/secret/payment paths).
Tasks:
- Apply
@Throttle/ThrottlerGuard (or the project's rate-limiting guard) to the sensitive handlers in src/profile-completeness/profile-completeness.controller.ts.
- Wire any required configuration in
src/profile-completeness.
- Ensure a rate-limited request returns 429 with a clear message.
Impacted Files:
- src/profile-completeness/profile-completeness.controller.ts
- src/profile-completeness
Acceptance Criteria
- Exceeding the limit returns HTTP 429.
- Limits are documented and configurable, not hardcoded magic numbers.
- Normal usage is unaffected.
Overview
Endpoints in
src/profile-completeness/profile-completeness.controller.tsare sensitive (authentication, credential/secret handling, payment data, token redemption, or state-changing admin actions) and should be protected against brute-force and abuse with request throttling. Apply a rate-limit/throttler guard with limits appropriate to each endpoint.Specifications
Features:
Tasks:
@Throttle/ThrottlerGuard(or the project's rate-limiting guard) to the sensitive handlers insrc/profile-completeness/profile-completeness.controller.ts.src/profile-completeness.Impacted Files:
Acceptance Criteria