Skip to content

Setup Rate Limit for Login and Password Reset - #266

Open
Josiassejod1 wants to merge 8 commits into
TelosLabs:mainfrom
Josiassejod1:dalvin/rate-limit
Open

Setup Rate Limit for Login and Password Reset#266
Josiassejod1 wants to merge 8 commits into
TelosLabs:mainfrom
Josiassejod1:dalvin/rate-limit

Conversation

@Josiassejod1

Copy link
Copy Markdown

Description

This PR adds rate limiting to the user login and password reset routes using built in rails limiting. It returns a 429 if a user attempts too many incorrect login attempts along with resetting a password.

#95

I added memory_store to the test initializer because it wasn't allow me to set the memory store in the before block.

How has this been tested?

To test appropriately go to new_registration/new and try and sign in three times under a minute you should see an error you need to enable caching locally using rails dev:cache

Screenshot 2025-09-04 at 2 50 08 PM Screenshot 2025-09-04 at 2 47 14 PM
  • [X ] Manual testing
  • System tests
  • [ X] Unit tests
  • None

Checklist

  • [X ] CI pipeline is passing
  • X[ ] My code follows the conventions of this project
  • [X ] I have performed a self-review of my code
  • I have commented on my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation (if applicable)
  • I have added seed data to the database (if applicable)

Release tasks

Add any tasks that need to be done before/after the release of this feature.

Screenshots/Loom

This section is relevant in case we want to share progress with the team, otherwise, it can be omitted.

@Josiassejod1
Josiassejod1 marked this pull request as draft September 6, 2025 20:06
@Josiassejod1
Josiassejod1 marked this pull request as ready for review September 6, 2025 20:11
@Josiassejod1
Josiassejod1 marked this pull request as draft September 6, 2025 20:50
@Josiassejod1
Josiassejod1 marked this pull request as ready for review September 6, 2025 20:57
# Show full error reports and disable caching.
config.consider_all_requests_local = true
config.action_controller.perform_caching = false
config.cache_store = :null_store

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can't really test rate limiting without having this set unfortunately, so if there are any other suggestions I am open to it.

@ibramsterdam
ibramsterdam requested a review from Sergio-e October 14, 2025 19:01
@Josiassejod1

Copy link
Copy Markdown
Author

@Sergio-e @ibramsterdam any movement on this?

@ibramsterdam

Copy link
Copy Markdown
Contributor

@Josiassejod1 The PR looks good! But we still need to wait for @Sergio-e to review it and merge it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants