- Environment-split settings: base/local/test/prod with django-environ - Postgres + Redis + Celery wiring (broker, beat, result backend) - All 9 domain app stubs: accounts, courses, cms, tracking, quizzes, training, certificates, reports, notifications - api app: /healthz/ endpoint, custom DRF exception handler, SecurityAuditMiddleware, permissions/throttle/upload-validation stubs - DRF global baseline: JWT+session auth, closed-by-default permissions, cursor/page pagination, drf-spectacular schema generation - Dockerfile (multi-env build arg), docker-compose.yml (local), docker-compose.test.yml (CI-friendly tmpfs Postgres) - pytest.ini with smoke + settings marker definitions - tests/test_smoke.py: startup, URL resolution, healthcheck shape - tests/test_settings_matrix.py: per-profile security assertions - .github/workflows/ci.yml: test, lint, schema CI jobs - .env.example with all required vars documented - .gitignore Co-Authored-By: Paperclip <noreply@paperclip.ing>
20 lines
515 B
Python
20 lines
515 B
Python
from rest_framework.throttling import AnonRateThrottle, UserRateThrottle
|
|
|
|
|
|
class LoginRateThrottle(AnonRateThrottle):
|
|
"""Limits authentication attempts to prevent credential brute-force."""
|
|
|
|
scope = "login"
|
|
|
|
|
|
class UploadRateThrottle(UserRateThrottle):
|
|
"""Limits file upload requests per authenticated user to prevent abuse."""
|
|
|
|
scope = "upload"
|
|
|
|
|
|
class AbuseRateThrottle(AnonRateThrottle):
|
|
"""Aggressive limit for sensitive public endpoints (password reset, OTP, etc.)."""
|
|
|
|
scope = "abuse"
|