From d3bd1c87002b63401332344ed2984c710e5e90c6 Mon Sep 17 00:00:00 2001 From: HARSH KANANI <113297734+HarshXAI@users.noreply.github.com> Date: Sun, 22 Feb 2026 07:55:32 +0530 Subject: [PATCH] =?UTF-8?q?fix(vesper-api-gateway):=20Missing=20rate=20lim?= =?UTF-8?q?iting=20=E2=80=94=20auto-generated=20by=20KA-CHOW?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../Missing-rate-limiting.patch.ts | 41 +++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 kachow-patches/vesper-api-gateway/Missing-rate-limiting.patch.ts diff --git a/kachow-patches/vesper-api-gateway/Missing-rate-limiting.patch.ts b/kachow-patches/vesper-api-gateway/Missing-rate-limiting.patch.ts new file mode 100644 index 0000000..a79d41c --- /dev/null +++ b/kachow-patches/vesper-api-gateway/Missing-rate-limiting.patch.ts @@ -0,0 +1,41 @@ +/** + * KA-CHOW Auto-Patch + * Issue: Missing rate limiting + * Service: vesper-api-gateway + * + * The code introduces a rate limiting decorator that tracks the number of requests from each client IP within a 60-second window. It maintains a dictionary to store timestamps of requests for each IP. When a request is made, it filters out timestamps older than 60 seconds and checks if the number of requests exceeds the limit of 100. If it does, it returns a 429 error. Otherwise, it appends the current timestamp and processes the request. This change prevents abuse by limiting excessive requests while preserving existing functionality. + */ + +from flask import Flask, request, jsonify +from functools import wraps +from time import time + +app = Flask(__name__) + +RATE_LIMIT = 100 +TIME_WINDOW = 60 +client_requests = {} + + +def rate_limit(func): + @wraps(func) + def wrapper(*args, **kwargs): + client_ip = request.remote_addr + current_time = time() + if client_ip not in client_requests: + client_requests[client_ip] = [] + # Filter out requests that are outside the time window + client_requests[client_ip] = [timestamp for timestamp in client_requests[client_ip] if current_time - timestamp < TIME_WINDOW] + if len(client_requests[client_ip]) >= RATE_LIMIT: + return jsonify({'error': 'Too many requests'}), 429 + client_requests[client_ip].append(current_time) + return func(*args, **kwargs) + return wrapper + +@app.route('/public-endpoint') +@rate_limit +def public_endpoint(): + return jsonify({'message': 'This is a public endpoint'}) + +if __name__ == '__main__': + app.run() \ No newline at end of file