fix: rate limiting по пользователям из JWT + cleanup WebPush подписок и cooldown sync-push
This commit is contained in:
@@ -480,6 +480,23 @@ export class ContentStorage extends DataTablesStorage {
|
||||
async registerWebPushSubscription(userId: number, organizationId: number, endpoint: string, subscription: string): Promise<void> {
|
||||
await db.delete(webPushSubscriptions).where(eq(webPushSubscriptions.endpoint, endpoint));
|
||||
await db.insert(webPushSubscriptions).values({ userId, organizationId, endpoint, subscription });
|
||||
|
||||
// Keep at most 3 subscriptions per user to prevent stale devices from
|
||||
// accumulating and receiving unnecessary sync pushes.
|
||||
const MAX_SUBSCRIPTIONS_PER_USER = 3;
|
||||
const userSubs = await db
|
||||
.select({ id: webPushSubscriptions.id })
|
||||
.from(webPushSubscriptions)
|
||||
.where(and(
|
||||
eq(webPushSubscriptions.userId, userId),
|
||||
eq(webPushSubscriptions.organizationId, organizationId)
|
||||
))
|
||||
.orderBy(webPushSubscriptions.id);
|
||||
|
||||
if (userSubs.length > MAX_SUBSCRIPTIONS_PER_USER) {
|
||||
const toDelete = userSubs.slice(0, userSubs.length - MAX_SUBSCRIPTIONS_PER_USER).map(s => s.id);
|
||||
await db.delete(webPushSubscriptions).where(inArray(webPushSubscriptions.id, toDelete));
|
||||
}
|
||||
}
|
||||
|
||||
async unregisterWebPushSubscription(endpoint: string): Promise<void> {
|
||||
|
||||
Reference in New Issue
Block a user