feat(auth): add signIn rate-limit backfill with dual ip/account budgets
Wires the rate-limit primitive end-to-end through auth.signIn as the
canonical credential-stuffing defence example:
- manifest: rateLimit [ip 5/1m, account 10/1h] on signIn use case
- use case: rateLimit: IRateLimit dep; dual consume + TooManyRequestsError
- binders: ctx.rateLimit ?? new NoopRateLimit() in bind-production + bind-dev-seed
- tRPC: TooManyRequestsError → TOO_MANY_REQUESTS error code in authProcedure
- tests: RecordingRateLimit dual-consume assertion; InMemoryRateLimit
budget-1 ip + account rejection; coverage 100% on use-cases layer
- ESLint: _manifest-ast.js extractRateLimitNames handles RateLimitBudget
objects ({name,window,budget}) in addition to plain string literals,
no-undeclared-rate-limit passes on both "ip" and "account" call sites
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -6,9 +6,14 @@ import {
|
||||
} from "@/application/use-cases/sign-in.use-case";
|
||||
import { MockUsersRepository } from "@/infrastructure/repositories/users.repository.mock";
|
||||
import { MockAuthenticationService } from "@/infrastructure/services/authentication.service.mock";
|
||||
import { AuthenticationError } from "@/entities/errors/auth";
|
||||
import {
|
||||
AuthenticationError,
|
||||
TooManyRequestsError,
|
||||
} from "@/entities/errors/auth";
|
||||
import type { IAuthenticationService } from "@/application/services/authentication.service.interface";
|
||||
import { userFactory } from "@/__factories__/user.factory";
|
||||
import { NoopRateLimit, InMemoryRateLimit } from "@repo/core-shared/rate-limit";
|
||||
import { RecordingRateLimit } from "@repo/core-testing/rate-limit";
|
||||
|
||||
describe("signInUseCase", () => {
|
||||
it("returns a session + cookie on valid credentials", async () => {
|
||||
@@ -20,7 +25,7 @@ describe("signInUseCase", () => {
|
||||
});
|
||||
await users.createUser(seedUser);
|
||||
|
||||
const useCase = signInUseCase(users, auth);
|
||||
const useCase = signInUseCase(users, auth, new NoopRateLimit());
|
||||
const result = await useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
@@ -33,7 +38,7 @@ describe("signInUseCase", () => {
|
||||
it("throws AuthenticationError when user does not exist", async () => {
|
||||
const users = new MockUsersRepository([]);
|
||||
const auth = new MockAuthenticationService(users);
|
||||
const useCase = signInUseCase(users, auth);
|
||||
const useCase = signInUseCase(users, auth, new NoopRateLimit());
|
||||
|
||||
await expect(
|
||||
useCase({ username: "ghost", password: "anything" }),
|
||||
@@ -50,11 +55,99 @@ describe("signInUseCase", () => {
|
||||
}),
|
||||
);
|
||||
|
||||
const useCase = signInUseCase(users, auth);
|
||||
const useCase = signInUseCase(users, auth, new NoopRateLimit());
|
||||
await expect(
|
||||
useCase({ username: "alice", password: "wrong" }),
|
||||
).rejects.toBeInstanceOf(AuthenticationError);
|
||||
});
|
||||
|
||||
it("captures both ip and account consume calls via RecordingRateLimit", async () => {
|
||||
const users = new MockUsersRepository([]);
|
||||
const auth = new MockAuthenticationService(users);
|
||||
const rl = new RecordingRateLimit();
|
||||
const seedUser = userFactory.build({
|
||||
username: "alice",
|
||||
passwordHash: "hashed_testpassword",
|
||||
});
|
||||
await users.createUser(seedUser);
|
||||
|
||||
const useCase = signInUseCase(users, auth, rl);
|
||||
await useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
clientIp: "1.2.3.4",
|
||||
});
|
||||
|
||||
expect(rl.consumeCalls).toHaveLength(2);
|
||||
expect(rl.consumeCalls[0]).toMatchObject({
|
||||
budgetName: "ip",
|
||||
key: "signIn:ip:1.2.3.4",
|
||||
});
|
||||
expect(rl.consumeCalls[1]).toMatchObject({
|
||||
budgetName: "account",
|
||||
key: "signIn:account:alice",
|
||||
});
|
||||
});
|
||||
|
||||
it("throws TooManyRequestsError when ip budget is exhausted", async () => {
|
||||
const users = new MockUsersRepository([]);
|
||||
const auth = new MockAuthenticationService(users);
|
||||
const rl = new InMemoryRateLimit([
|
||||
{ name: "ip", window: "1m", budget: 1 },
|
||||
{ name: "account", window: "1h", budget: 10 },
|
||||
]);
|
||||
const seedUser = userFactory.build({
|
||||
username: "alice",
|
||||
passwordHash: "hashed_testpassword",
|
||||
});
|
||||
await users.createUser(seedUser);
|
||||
|
||||
const useCase = signInUseCase(users, auth, rl);
|
||||
await useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
clientIp: "1.2.3.4",
|
||||
});
|
||||
|
||||
await expect(
|
||||
useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
clientIp: "1.2.3.4",
|
||||
}),
|
||||
).rejects.toBeInstanceOf(TooManyRequestsError);
|
||||
});
|
||||
|
||||
it("throws TooManyRequestsError when account budget is exhausted", async () => {
|
||||
const users = new MockUsersRepository([]);
|
||||
const auth = new MockAuthenticationService(users);
|
||||
const rl = new InMemoryRateLimit([
|
||||
{ name: "ip", window: "1m", budget: 100 },
|
||||
{ name: "account", window: "1h", budget: 1 },
|
||||
]);
|
||||
const seedUser = userFactory.build({
|
||||
username: "alice",
|
||||
passwordHash: "hashed_testpassword",
|
||||
});
|
||||
await users.createUser(seedUser);
|
||||
|
||||
const useCase = signInUseCase(users, auth, rl);
|
||||
// First call succeeds (ip allows, account allows, credentials ok)
|
||||
await useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
clientIp: "1.2.3.4",
|
||||
});
|
||||
|
||||
// Second call: ip still allows (high budget), account is exhausted
|
||||
await expect(
|
||||
useCase({
|
||||
username: "alice",
|
||||
password: "testpassword",
|
||||
clientIp: "5.6.7.8",
|
||||
}),
|
||||
).rejects.toBeInstanceOf(TooManyRequestsError);
|
||||
});
|
||||
});
|
||||
|
||||
describe("signInUseCase output validation", () => {
|
||||
@@ -69,7 +162,7 @@ describe("signInUseCase output validation", () => {
|
||||
createSession: async () => ({ session: { id: 123 }, cookie: null }),
|
||||
} as unknown as IAuthenticationService;
|
||||
|
||||
const useCase = signInUseCase(users, auth);
|
||||
const useCase = signInUseCase(users, auth, new NoopRateLimit());
|
||||
await expect(
|
||||
useCase({ username: "alice", password: "x" }),
|
||||
).rejects.toBeInstanceOf(ZodError);
|
||||
|
||||
@@ -1,6 +1,10 @@
|
||||
import { z } from "zod";
|
||||
|
||||
import { AuthenticationError } from "../../entities/errors/auth";
|
||||
import type { IRateLimit } from "@repo/core-shared/rate-limit";
|
||||
import {
|
||||
AuthenticationError,
|
||||
TooManyRequestsError,
|
||||
} from "../../entities/errors/auth";
|
||||
import { cookieSchema } from "../../entities/models/cookie";
|
||||
import { sessionSchema } from "../../entities/models/session";
|
||||
import type { IUsersRepository } from "../repositories/users.repository.interface";
|
||||
@@ -11,6 +15,7 @@ export const signInInputSchema = z
|
||||
.object({
|
||||
username: z.string().min(3).max(31),
|
||||
password: z.string().min(6).max(255),
|
||||
clientIp: z.string().optional(),
|
||||
})
|
||||
.strict();
|
||||
export type SignInInput = z.infer<typeof signInInputSchema>;
|
||||
@@ -26,9 +31,28 @@ export type SignInOutput = z.infer<typeof signInOutputSchema>;
|
||||
export type ISignInUseCase = ReturnType<typeof signInUseCase>;
|
||||
|
||||
export const signInUseCase =
|
||||
(usersRepository: IUsersRepository, authenticationService: IAuthenticationService) =>
|
||||
(
|
||||
usersRepository: IUsersRepository,
|
||||
authenticationService: IAuthenticationService,
|
||||
rateLimit: IRateLimit,
|
||||
) =>
|
||||
async (input: SignInInput): Promise<SignInOutput> => {
|
||||
const existingUser = await usersRepository.getUserByUsername(input.username);
|
||||
const { allowed: ipAllowed } = await rateLimit.consume(
|
||||
"ip",
|
||||
`signIn:ip:${input.clientIp ?? ""}`,
|
||||
);
|
||||
if (!ipAllowed) throw new TooManyRequestsError("Too many sign-in attempts");
|
||||
|
||||
const { allowed: accountAllowed } = await rateLimit.consume(
|
||||
"account",
|
||||
`signIn:account:${input.username}`,
|
||||
);
|
||||
if (!accountAllowed)
|
||||
throw new TooManyRequestsError("Too many sign-in attempts");
|
||||
|
||||
const existingUser = await usersRepository.getUserByUsername(
|
||||
input.username,
|
||||
);
|
||||
if (!existingUser) {
|
||||
throw new AuthenticationError("User does not exist");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user