fix(api): add rate limiting, file size validation, and timeout handling

- Add Content-Length header check for early file size validation on audio upload
- Add rate limiting (60 req/min) to public watch endpoint
- Add 10-second timeout with AbortController for YouTube and Vimeo oEmbed requests
- Add automatic rate limit cleanup interval for self-hosted servers
- Fix null check for comment.replies in video page content
- Add checkWorkspaceAccess helper for workspace authorization
This commit is contained in:
Yusuf İpek
2026-02-14 15:59:30 +03:00
parent 413fc9cec6
commit 20005f1a15
8 changed files with 68 additions and 4 deletions
+8
View File
@@ -160,6 +160,14 @@ export async function cleanupRateLimits(): Promise<void> {
}
}
// Start cleanup interval when the module is loaded (for self-hosted servers)
// Cleanup runs every 5 minutes to remove expired rate limit entries
if (typeof setInterval !== 'undefined') {
setInterval(() => {
cleanupRateLimits().catch(console.error);
}, 5 * 60 * 1000);
}
/**
* One-call rate limit check that returns a 429 NextResponse if blocked, or null if allowed.
* Use at the top of any API handler: