Skip to content

Apply rate limiting to profile-completeness endpoints #1330

Description

@RUKAYAT-CODER

Overview

Endpoints in src/profile-completeness/profile-completeness.controller.ts are sensitive (authentication, credential/secret handling, payment data, token redemption, or state-changing admin actions) and should be protected against brute-force and abuse with request throttling. Apply a rate-limit/throttler guard with limits appropriate to each endpoint.

Specifications

Features:

  • Sensitive handlers are covered by a throttling guard.
  • Limits are tuned per endpoint (stricter on auth/secret/payment paths).

Tasks:

  • Apply @Throttle/ThrottlerGuard (or the project's rate-limiting guard) to the sensitive handlers in src/profile-completeness/profile-completeness.controller.ts.
  • Wire any required configuration in src/profile-completeness.
  • Ensure a rate-limited request returns 429 with a clear message.

Impacted Files:

  • src/profile-completeness/profile-completeness.controller.ts
  • src/profile-completeness

Acceptance Criteria

  • Exceeding the limit returns HTTP 429.
  • Limits are documented and configurable, not hardcoded magic numbers.
  • Normal usage is unaffected.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions