feat(backend): add throtteling by default

This commit is contained in:
Matthias Mair 2026-05-15 20:25:50 +02:00
parent 7655dc3819
commit 872c070822
No known key found for this signature in database
GPG Key ID: A593429DDA23B66A
3 changed files with 24 additions and 1 deletions

View File

@ -136,7 +136,8 @@ Depending on how your InvenTree installation is configured, you will need to pay
| `INVENTREE_X_FORWARDED_PROTO_NAME` | `x_forwarded_proto_name` | `HTTP_X_FORWARDED_PROTO` | Name of the header to use for forwarded protocol information |
{{ configsetting("INVENTREE_SESSION_COOKIE_SECURE") }} Enforce secure session cookies |
{{ configsetting("INVENTREE_COOKIE_SAMESITE") }} Session cookie mode. Must be one of `Strict | Lax | None | False`. Refer to the [mozilla developer docs](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie) and the [django documentation]({% include "django.html" %}/ref/settings/#std-setting-SESSION_COOKIE_SAMESITE) for more information. |
{{ configsetting("INVENTREE_THROTTLE_ANON") }} Throttle rate for anonymous users (e.g. '20/minute') |
{{ configsetting("INVENTREE_THROTTLE_USER") }} Throttle rate for authenticated users (e.g. '5/second') |
### Debug Mode

View File

@ -525,6 +525,8 @@ REST_FRAMEWORK = {
'DEFAULT_METADATA_CLASS': 'InvenTree.metadata.InvenTreeMetadata',
'DEFAULT_RENDERER_CLASSES': ['rest_framework.renderers.JSONRenderer'],
'TOKEN_MODEL': 'users.models.ApiToken',
'DEFAULT_THROTTLE_CLASSES': [],
'DEFAULT_THROTTLE_RATES': {},
}
if DEBUG:
@ -540,6 +542,21 @@ if USE_JWT:
JWT_AUTH_REFRESH_COOKIE = 'inventree-token'
INSTALLED_APPS.append('rest_framework_simplejwt')
# Throtteling setup
THROTTLE_ANON = get_setting('INVENTREE_THROTTLE_ANON', 'throttle.anon', '20/minute')
THROTTLE_USER = get_setting('INVENTREE_THROTTLE_USER', 'throttle.user', '20/second')
if THROTTLE_ANON and str(THROTTLE_ANON).lower() != 'none':
REST_FRAMEWORK['DEFAULT_THROTTLE_RATES']['anon'] = THROTTLE_ANON
REST_FRAMEWORK['DEFAULT_THROTTLE_CLASSES'].append(
'rest_framework.throttling.AnonRateThrottle'
)
if THROTTLE_USER and str(THROTTLE_USER).lower() != 'none':
REST_FRAMEWORK['DEFAULT_THROTTLE_RATES']['user'] = THROTTLE_USER
REST_FRAMEWORK['DEFAULT_THROTTLE_CLASSES'].append(
'rest_framework.throttling.UserRateThrottle'
)
# WSGI default setting
WSGI_APPLICATION = 'InvenTree.wsgi.application'

View File

@ -162,6 +162,11 @@ cors:
# regex:
# Throttling is applied to the API by default to make DoS attacks more difficult; these can be disabled by setting them to None.
# throttle:
# anon: '20/minute'
# user: '20/second'
# MEDIA_ROOT is the local filesystem location for storing uploaded files
#media_root: '/home/inventree/data/media'