Files
apartment-dashboard-api/__tests__/scraper
Stephen Minakian a05c844b93
All checks were successful
CI/CD Pipeline - Apartment API / Lint & Test (pull_request) Successful in 43s
CI/CD Pipeline - Apartment API / Send Webhook Notification (pull_request) Successful in 2s
CI/CD Pipeline - Apartment API / Build & Push Image (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Scan Dependencies (pull_request) Successful in 13s
Add per-user rate limiting to scraper trigger endpoint
Implement rate limiting for POST /api/admin/scraper/run with a cap of
5 requests per hour per admin user. When exceeded, the endpoint returns
429 Too Many Requests with a Retry-After header indicating seconds
until the window resets.

Rate limit tracking uses an in-memory Map keyed by user ID. The check
runs before the mutex check so rate-limited users get a 429 rather
than a misleading 409 conflict. Scheduled/cron-triggered runs are not
counted against any user's limit.

Adds 6 new tests covering: allow up to 5 requests, reject 6th with
429, Retry-After header presence, per-user isolation, window expiry
reset, and rate-limit-before-mutex ordering.
2026-02-06 23:15:31 -07:00
..