Implement Sprint 2 security enhancements
Add user-based rate limiting middleware (100 req/min) for authenticated endpoints using httprate library. Implement common password validation blocking 50+ weak passwords. Improve test coverage from 38.3% to 44.6% with comprehensive refresh token tests. Security improvements: - Rate limiting by user ID for /habits and /stats endpoints - X-RateLimit-Limit header in responses - Common password blacklist in password validation - Refresh token test suite with 5 scenarios (valid, invalid, expired, revoked, empty)
This commit is contained in:
@@ -14,14 +14,14 @@ type Claims struct {
|
||||
}
|
||||
|
||||
type JWTService struct {
|
||||
secret []byte
|
||||
expiry time.Duration
|
||||
secret []byte
|
||||
expiry time.Duration
|
||||
}
|
||||
|
||||
func NewJWTService(secret string, expiryHours int) *JWTService {
|
||||
return &JWTService{
|
||||
secret: []byte(secret),
|
||||
expiry: time.Duration(expiryHours) * time.Hour,
|
||||
secret: []byte(secret),
|
||||
expiry: time.Duration(expiryHours) * time.Hour,
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user