Skip to content

security: harden API and WebSocket rate limits - #93

Open
khemssharma wants to merge 6 commits into
mainfrom
hardening/rate-limits-ws-abuse
Open

khemssharma wants to merge 6 commits into
mainfrom
hardening/rate-limits-ws-abuse

Conversation

@khemssharma

Copy link
Copy Markdown
Owner

What this changes

  • Add Redis-backed rate limits for Stockfish analysis, AI analysis/chat/session, and puzzle attempts.
  • Keep auth brute-force protection in place with configurable limits.
  • Add Redis-shared WebSocket connection caps per authenticated user and IP.
  • Reject invalid JWTs on WebSocket connections instead of downgrading them to anonymous guests.
  • Fail closed for protected Redis-backed rate-limit/connection-limit checks.

Default limits

  • Auth: 20 requests / 15 minutes / IP
  • Stockfish analysis: 10 / minute / authenticated user
  • AI endpoints: 20 / minute / authenticated user
  • Puzzle attempts: 30 / minute / authenticated user
  • WebSockets: 5 / user, 20 / IP

Limits can be overridden with environment variables.

Safety

This PR targets the hardening branch only and does not modify main.

This branch had an error being deployed

1 failed deployment
hardening/rate-limits-ws-abuse - Chess PR #93 — 3930c7f0 Deployed Sep 24, 2026 by khemssharma
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant