summaryrefslogtreecommitdiffstats
path: root/config
diff options
context:
space:
mode:
authorEugen Rochko <eugen@zeonfederated.com>2021-03-01 18:39:47 +0100
committerGitHub <noreply@github.com>2021-03-01 18:39:47 +0100
commitee1119208c613b9ded7ebfb2a5a7b8bd5a5ef008 (patch)
treebecd592fb3d5015681a31613d74d73a132609740 /config
parent287aa75f2ecc9bbbb75047e96e64882d8d14fd82 (diff)
Add `POST /api/v1/emails/confirmations` to REST API (#15816)
Only available to the application the user originally signed-up with
Diffstat (limited to 'config')
-rw-r--r--config/initializers/rack_attack.rb8
-rw-r--r--config/routes.rb4
2 files changed, 10 insertions, 2 deletions
diff --git a/config/initializers/rack_attack.rb b/config/initializers/rack_attack.rb
index c0db499072f..2a6cca7dc8c 100644
--- a/config/initializers/rack_attack.rb
+++ b/config/initializers/rack_attack.rb
@@ -94,11 +94,15 @@ class Rack::Attack
end
throttle('throttle_email_confirmations/ip', limit: 25, period: 5.minutes) do |req|
- req.remote_ip if req.post? && req.path == '/auth/confirmation'
+ req.remote_ip if req.post? && %w(/auth/confirmation /api/v1/emails/confirmations).include?(req.path)
end
throttle('throttle_email_confirmations/email', limit: 5, period: 30.minutes) do |req|
- req.params.dig('user', 'email').presence if req.post? && req.path == '/auth/password'
+ if req.post? && req.path == '/auth/password'
+ req.params.dig('user', 'email').presence
+ elsif req.post? && req.path == '/api/v1/emails/confirmations'
+ req.authenticated_user_id
+ end
end
throttle('throttle_login_attempts/ip', limit: 25, period: 5.minutes) do |req|
diff --git a/config/routes.rb b/config/routes.rb
index 0ff48cf482e..780a52b0ced 100644
--- a/config/routes.rb
+++ b/config/routes.rb
@@ -403,6 +403,10 @@ Rails.application.routes.draw do
resources :apps, only: [:create]
+ namespace :emails do
+ resources :confirmations, only: [:create]
+ end
+
resource :instance, only: [:show] do
resources :peers, only: [:index], controller: 'instances/peers'
resource :activity, only: [:show], controller: 'instances/activity'