From f81f8ca0323642cdacbc20dd51badba99c60d311 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adri=C3=A0=20Casaj=C3=BAs?= Date: Tue, 21 Nov 2023 17:44:33 +0100 Subject: [PATCH] Further limit the index endpoint (#1950) --- app/api/views/alias.py | 2 +- app/dashboard/views/index.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/app/api/views/alias.py b/app/api/views/alias.py index 6adc9ad3..9e593f31 100644 --- a/app/api/views/alias.py +++ b/app/api/views/alias.py @@ -73,7 +73,7 @@ def get_aliases(): @api_bp.route("/v2/aliases", methods=["GET", "POST"]) @limiter.limit( - "15/minute", + "5/minute", ) @require_api_auth def get_aliases_v2(): diff --git a/app/dashboard/views/index.py b/app/dashboard/views/index.py index 24286dba..6a145332 100644 --- a/app/dashboard/views/index.py +++ b/app/dashboard/views/index.py @@ -58,7 +58,7 @@ def get_stats(user: User) -> Stats: exempt_when=lambda: request.form.get("form-name") != "create-random-email", ) @limiter.limit( - "10/minute", + "5/minute", methods=["GET"], ) @login_required