Files
accounted/lib/api/token-rate-limit.ts
Jakob Wennberg f266c386f3 chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers (#2150)
* chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers

Remove 33 dead files, ~270 unreferenced exports/types, 13 dead i18n
namespaces and 4 unused dependencies; fold byte-identical helper copies
into one canonical home each (lib/utils chunk/sleep/utcDateStamp,
lib/dates/iso, lib/invariants/uuid, lib/xml/escape, lib/reports/sru/format,
lib/pdf/number-text, lib/browser/panel-request, lib/api/v1/body +
v1ValidationError rolled out to ~55 v1 routes, booking-template schemas).

No behaviour change: v1 bodies and status codes, MCP tool schemas, DB
writes and money math are untouched. Naive ore rounding was deliberately
not swapped for roundOre; see DECISIONS.md 2026-09-02 for the full list
of things left alone on purpose.

tsc, lint, 19588 unit tests and check:guards green; antipattern baseline
ratcheted (naive-ore-round 622 -> 620, hand-rolled-invariant 115 -> 113).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(transactions): import RawTransaction from @/types after the ingest re-export removal

CI's type ratchet (check:types, full tsconfig) caught the one test file
that still imported the type through lib/transactions/ingest.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 11:51:16 +02:00

41 lines
1.4 KiB
TypeScript

/**
* In-memory per-token rate limiter for the public token-authenticated routes
* (calendar feed, payslip PDF). The token IS the authentication on those
* routes, so the limit is keyed by token, not by user.
*
* Process-local by design: a multi-instance deploy limits per instance, which
* is acceptable for these low-value endpoints. Each route creates its own
* limiter so the maps stay isolated.
*/
export function createTokenRateLimiter(options: { max: number; windowMs: number; cleanupEveryMs?: number }) {
const { max, windowMs, cleanupEveryMs = 5 * 60_000 } = options
const entries = new Map<string, { count: number; resetAt: number }>()
let lastCleanup = Date.now()
// Periodic sweep of expired entries so the map cannot grow without bound.
function cleanup() {
const now = Date.now()
if (now - lastCleanup < cleanupEveryMs) return
lastCleanup = now
for (const [key, value] of entries) {
if (now > value.resetAt) entries.delete(key)
}
}
return {
/** Count one request for `token`; false when the window's budget is spent. */
allow(token: string): boolean {
cleanup()
const nowMs = Date.now()
const entry = entries.get(token)
if (entry && nowMs < entry.resetAt) {
if (entry.count >= max) return false
entry.count++
} else {
entries.set(token, { count: 1, resetAt: nowMs + windowMs })
}
return true
},
}
}