v0.2.8: XSS净化 + 速率限制修复
- 搜索关键词存储前HTML标签剥离 - 速率限制keyGenerator改用getClientIP(读X-Forwarded-For) - 搜索限流从150/min降至60/min - 清理数据库中历史XSS条目
This commit is contained in:
@@ -51,3 +51,6 @@ const defaultLimiter = rateLimit({
|
||||
});
|
||||
|
||||
export default defaultLimiter;
|
||||
|
||||
// NOTE v0.2.8: Fixed keyGenerator to use getClientIP() instead of req.socket.remoteAddress
|
||||
// This ensures rate limiting works correctly behind reverse proxy (OpenResty)
|
||||
|
||||
Reference in New Issue
Block a user