fix(api): add rate limiting, file size validation, and timeout handling

- Add Content-Length header check for early file size validation on audio upload
- Add rate limiting (60 req/min) to public watch endpoint
- Add 10-second timeout with AbortController for YouTube and Vimeo oEmbed requests
- Add automatic rate limit cleanup interval for self-hosted servers
- Fix null check for comment.replies in video page content
- Add checkWorkspaceAccess helper for workspace authorization
This commit is contained in:
Yusuf İpek
2026-02-14 15:59:30 +03:00
parent 413fc9cec6
commit 20005f1a15
8 changed files with 68 additions and 4 deletions
+30
View File
@@ -125,3 +125,33 @@ export async function checkProjectAccess(
canDelete,
};
}
// Helper to check workspace access
export async function checkWorkspaceAccess(
workspace: { id: string; ownerId: string },
userId: string | undefined
) {
const isOwner = userId === workspace.ownerId;
// Get workspace membership
const workspaceMember = userId
? await db.workspaceMember.findUnique({
where: { workspaceId_userId: { workspaceId: workspace.id, userId } },
})
: null;
const isMember = !!workspaceMember;
const isAdmin = workspaceMember?.role === WorkspaceMemberRole.ADMIN;
const hasAccess = isOwner || isMember;
const canEdit = isOwner || isAdmin;
const canDelete = isOwner;
return {
isOwner,
isMember,
isAdmin,
hasAccess,
canEdit,
canDelete,
};
}