forked from retoor/devplacepy
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
85cf634e60 | ||
|
|
aa178a8c62 |
File diff suppressed because one or more lines are too long
@@ -1070,6 +1070,7 @@ def init_db():
|
||||
("planted_at", ""),
|
||||
("ready_at", ""),
|
||||
("watered_by", "[]"),
|
||||
("cooldown_until", ""),
|
||||
("created_at", ""),
|
||||
("updated_at", ""),
|
||||
):
|
||||
@@ -1077,6 +1078,18 @@ def init_db():
|
||||
game_plots.create_column_by_example(column, example)
|
||||
_index(db, "game_plots", "idx_game_plots_farm", ["farm_uid", "slot_index"])
|
||||
|
||||
_drop_index(db, "idx_rate_limit_log_user_ts")
|
||||
rate_limit_log = get_table("rate_limit_log")
|
||||
for column, example in (
|
||||
("uid", ""),
|
||||
("user_uid", ""),
|
||||
("action", ""),
|
||||
("timestamp", ""),
|
||||
):
|
||||
if not rate_limit_log.has_column(column):
|
||||
rate_limit_log.create_column_by_example(column, example)
|
||||
_index(db, "rate_limit_log", "idx_rate_limit_log_user_ts", ["user_uid", "timestamp"])
|
||||
|
||||
_index(db, "posts", "idx_posts_user_created", ["user_uid", "created_at"])
|
||||
_index(
|
||||
db,
|
||||
|
||||
@@ -1,10 +1,12 @@
|
||||
# retoor <retoor@molodetz.nl>
|
||||
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from typing import Annotated
|
||||
|
||||
from fastapi import APIRouter, Form, HTTPException, Request
|
||||
from fastapi.responses import HTMLResponse, JSONResponse, RedirectResponse
|
||||
|
||||
from devplacepy.database import db, get_table
|
||||
from devplacepy.models import GameSlotForm
|
||||
from devplacepy.responses import json_error, respond, wants_json
|
||||
from devplacepy.schemas import GameFarmViewOut
|
||||
@@ -18,6 +20,33 @@ from devplacepy.utils import (
|
||||
|
||||
from ._shared import game_seo, notify_farm, owner_by_username
|
||||
|
||||
_MAX_ACTIONS_PER_MINUTE = 30
|
||||
_RATE_WINDOW_SECONDS = 60
|
||||
|
||||
|
||||
def _check_farm_rate_limit(user_uid: str) -> None:
|
||||
cutoff = (datetime.now(timezone.utc) - timedelta(seconds=_RATE_WINDOW_SECONDS)).isoformat()
|
||||
result = list(
|
||||
db.query(
|
||||
"SELECT COUNT(*) AS c FROM rate_limit_log"
|
||||
" WHERE user_uid = :uid AND timestamp >= :cutoff",
|
||||
uid=user_uid,
|
||||
cutoff=cutoff,
|
||||
)
|
||||
)
|
||||
count = result[0]["c"] if result else 0
|
||||
if count >= _MAX_ACTIONS_PER_MINUTE:
|
||||
raise HTTPException(
|
||||
status_code=429,
|
||||
detail="Rate limit exceeded. Max 30 actions per minute.",
|
||||
)
|
||||
get_table("rate_limit_log").insert({
|
||||
"user_uid": user_uid,
|
||||
"action": "",
|
||||
"timestamp": datetime.now(timezone.utc).isoformat(),
|
||||
})
|
||||
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
|
||||
@@ -53,6 +82,7 @@ async def water_farm(
|
||||
request: Request, username: str, data: Annotated[GameSlotForm, Form()]
|
||||
):
|
||||
viewer = require_user(request)
|
||||
_check_farm_rate_limit(viewer["uid"])
|
||||
owner = owner_by_username(username)
|
||||
if not owner:
|
||||
raise HTTPException(status_code=404, detail="Farm not found")
|
||||
@@ -77,6 +107,7 @@ async def steal_farm(
|
||||
request: Request, username: str, data: Annotated[GameSlotForm, Form()]
|
||||
):
|
||||
viewer = require_user(request)
|
||||
_check_farm_rate_limit(viewer["uid"])
|
||||
owner = owner_by_username(username)
|
||||
if not owner:
|
||||
raise HTTPException(status_code=404, detail="Farm not found")
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
# retoor <retoor@molodetz.nl>
|
||||
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from typing import Annotated
|
||||
|
||||
from fastapi import APIRouter, Form, Request
|
||||
from fastapi import APIRouter, Form, HTTPException, Request
|
||||
from fastapi.responses import HTMLResponse, JSONResponse, RedirectResponse
|
||||
|
||||
from devplacepy.models import (
|
||||
@@ -12,7 +13,7 @@ from devplacepy.models import (
|
||||
GameQuestForm,
|
||||
GameSlotForm,
|
||||
)
|
||||
from devplacepy.database import mark_notifications_read_by_target
|
||||
from devplacepy.database import db, get_table, mark_notifications_read_by_target
|
||||
from devplacepy.responses import json_error, respond, wants_json
|
||||
from devplacepy.schemas import GameLeaderboardOut, GameStateOut
|
||||
from devplacepy.services.game import GameError, store
|
||||
@@ -20,6 +21,33 @@ from devplacepy.utils import award_rewards, get_current_user, require_user, trac
|
||||
|
||||
from ._shared import game_seo, notify_farm, state_payload
|
||||
|
||||
_MAX_ACTIONS_PER_MINUTE = 30
|
||||
_RATE_WINDOW_SECONDS = 60
|
||||
|
||||
|
||||
def _check_rate_limit(user_uid: str) -> None:
|
||||
cutoff = (datetime.now(timezone.utc) - timedelta(seconds=_RATE_WINDOW_SECONDS)).isoformat()
|
||||
result = list(
|
||||
db.query(
|
||||
"SELECT COUNT(*) AS c FROM rate_limit_log"
|
||||
" WHERE user_uid = :uid AND timestamp >= :cutoff",
|
||||
uid=user_uid,
|
||||
cutoff=cutoff,
|
||||
)
|
||||
)
|
||||
count = result[0]["c"] if result else 0
|
||||
if count >= _MAX_ACTIONS_PER_MINUTE:
|
||||
raise HTTPException(
|
||||
status_code=429,
|
||||
detail="Rate limit exceeded. Max 30 actions per minute.",
|
||||
)
|
||||
get_table("rate_limit_log").insert({
|
||||
"user_uid": user_uid,
|
||||
"action": "",
|
||||
"timestamp": datetime.now(timezone.utc).isoformat(),
|
||||
})
|
||||
|
||||
|
||||
router = APIRouter()
|
||||
|
||||
|
||||
@@ -58,6 +86,7 @@ async def game_leaderboard(request: Request):
|
||||
|
||||
|
||||
async def _respond_action(request: Request, user: dict, fn, on_success=None):
|
||||
_check_rate_limit(user["uid"])
|
||||
try:
|
||||
result = fn()
|
||||
except GameError as exc:
|
||||
|
||||
@@ -60,6 +60,18 @@ CONFIRM_REQUIRED = {
|
||||
"gateway_model_delete",
|
||||
"email_account_delete",
|
||||
"email_delete_message",
|
||||
"game_buy_plot",
|
||||
"game_claim_quest",
|
||||
"game_daily",
|
||||
"game_fertilize",
|
||||
"game_harvest",
|
||||
"game_plant",
|
||||
"game_prestige",
|
||||
"game_steal",
|
||||
"game_upgrade_ci",
|
||||
"game_upgrade_legacy",
|
||||
"game_upgrade_perk",
|
||||
"game_water",
|
||||
}
|
||||
|
||||
CONDITIONAL_CONFIRM = {
|
||||
|
||||
@@ -39,6 +39,9 @@ def plant(user: dict, slot: int, crop_key: str) -> dict:
|
||||
plot = _plot_at(farm["uid"], slot)
|
||||
if not plot:
|
||||
raise GameError("That plot does not exist.")
|
||||
cooldown = plot.get("cooldown_until", "")
|
||||
if cooldown and _now() < _parse_date(cooldown):
|
||||
raise GameError("This plot is on cooldown. Wait a moment before planting.")
|
||||
if plot.get("crop_key"):
|
||||
raise GameError("That plot is already in use.")
|
||||
coins = int(farm.get("coins", 0))
|
||||
@@ -85,6 +88,7 @@ def harvest(user: dict, slot: int) -> dict:
|
||||
"planted_at": "",
|
||||
"ready_at": "",
|
||||
"watered_by": "[]",
|
||||
"cooldown_until": _iso(now + timedelta(seconds=5)),
|
||||
"updated_at": _iso(now),
|
||||
},
|
||||
["uid"],
|
||||
|
||||
@@ -513,24 +513,6 @@ img {
|
||||
display: inline-block;
|
||||
}
|
||||
|
||||
.post-action-btn.is-loading,
|
||||
.comment-vote-btn.is-loading,
|
||||
.comment-action-btn.is-loading,
|
||||
.comment-form-submit.is-loading,
|
||||
.vote-star.is-loading,
|
||||
.poll-option.is-loading {
|
||||
pointer-events: none;
|
||||
}
|
||||
|
||||
.post-action-btn.is-loading .btn-spinner,
|
||||
.comment-vote-btn.is-loading .btn-spinner,
|
||||
.comment-action-btn.is-loading .btn-spinner,
|
||||
.comment-form-submit.is-loading .btn-spinner,
|
||||
.vote-star.is-loading .btn-spinner,
|
||||
.poll-option.is-loading .btn-spinner {
|
||||
display: inline-block;
|
||||
}
|
||||
|
||||
.badge {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
|
||||
@@ -22,6 +22,6 @@ export class BookmarkManager extends OptimisticAction {
|
||||
if (label) {
|
||||
label.textContent = result.saved ? "Saved" : "Save";
|
||||
}
|
||||
}, button);
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -23,10 +23,7 @@ export class CommentManager {
|
||||
const wrapper = form.closest(".comment");
|
||||
if (!wrapper) return;
|
||||
const button = form.querySelector("button[type='submit']");
|
||||
if (button) {
|
||||
button.disabled = true;
|
||||
button.classList.add("is-loading");
|
||||
}
|
||||
if (button) button.disabled = true;
|
||||
|
||||
const anchor = wrapper.previousElementSibling
|
||||
&& wrapper.previousElementSibling.classList.contains("comment")
|
||||
@@ -41,10 +38,7 @@ export class CommentManager {
|
||||
wrapper.remove();
|
||||
window.scrollTo({ top: Math.max(anchorTop, 0) });
|
||||
} catch (err) {
|
||||
if (button) {
|
||||
button.disabled = false;
|
||||
button.classList.remove("is-loading");
|
||||
}
|
||||
if (button) button.disabled = false;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -124,10 +118,7 @@ export class CommentManager {
|
||||
|
||||
async submitEdit(form, text) {
|
||||
const save = form.querySelector("button[type='submit']");
|
||||
if (save) {
|
||||
save.disabled = true;
|
||||
save.classList.add("is-loading");
|
||||
}
|
||||
if (save) save.disabled = true;
|
||||
const content = form.querySelector("textarea").value;
|
||||
try {
|
||||
const result = await Http.send(form.action, { content });
|
||||
@@ -141,10 +132,7 @@ export class CommentManager {
|
||||
form.remove();
|
||||
text.style.display = "";
|
||||
} catch (err) {
|
||||
if (save) {
|
||||
save.disabled = false;
|
||||
save.classList.remove("is-loading");
|
||||
}
|
||||
if (save) save.disabled = false;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -217,10 +205,7 @@ export class CommentManager {
|
||||
}
|
||||
form.addEventListener("submit", () => {
|
||||
const btn = form.querySelector("button[type='submit']");
|
||||
if (btn) {
|
||||
btn.disabled = true;
|
||||
btn.classList.add("is-loading");
|
||||
}
|
||||
if (btn) btn.disabled = true;
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,11 +4,7 @@ import { Http } from "./Http.js";
|
||||
import { Toast } from "./Toast.js";
|
||||
|
||||
export class OptimisticAction {
|
||||
async submit(url, params, errorTarget, render, button = null) {
|
||||
if (button) {
|
||||
button.disabled = true;
|
||||
button.classList.add("is-loading");
|
||||
}
|
||||
async submit(url, params, errorTarget, render) {
|
||||
try {
|
||||
const result = await Http.sendForm(url, params, { silent: true });
|
||||
if (render) render(result);
|
||||
@@ -17,19 +13,10 @@ export class OptimisticAction {
|
||||
console.error("optimistic action failed", error);
|
||||
if (errorTarget) Toast.flash(errorTarget, "Error", 1500);
|
||||
return null;
|
||||
} finally {
|
||||
if (button) {
|
||||
button.disabled = false;
|
||||
button.classList.remove("is-loading");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
async submitOptimistic(url, params, errorTarget, apply, revert, reconcile, button = null) {
|
||||
if (button) {
|
||||
button.disabled = true;
|
||||
button.classList.add("is-loading");
|
||||
}
|
||||
async submitOptimistic(url, params, errorTarget, apply, revert, reconcile) {
|
||||
apply();
|
||||
try {
|
||||
const result = await Http.sendForm(url, params, { silent: true });
|
||||
@@ -40,11 +27,6 @@ export class OptimisticAction {
|
||||
revert();
|
||||
if (errorTarget) Toast.flash(errorTarget, "Error", 1500);
|
||||
return null;
|
||||
} finally {
|
||||
if (button) {
|
||||
button.disabled = false;
|
||||
button.classList.remove("is-loading");
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -42,7 +42,7 @@ export class PollManager extends OptimisticAction {
|
||||
}
|
||||
const pollUid = poll.dataset.pollUid;
|
||||
const optionUid = option.dataset.optionUid;
|
||||
await this.submit(`/polls/${pollUid}/vote`, { option_uid: optionUid }, null, (result) => this.render(poll, result), option);
|
||||
await this.submit(`/polls/${pollUid}/vote`, { option_uid: optionUid }, null, (result) => this.render(poll, result));
|
||||
}
|
||||
|
||||
render(poll, result) {
|
||||
|
||||
@@ -75,7 +75,7 @@ export class ReactionBar extends OptimisticAction {
|
||||
const type = bar.dataset.reactionType;
|
||||
const uid = bar.dataset.reactionUid;
|
||||
const emoji = trigger.dataset.reactionEmoji;
|
||||
await this.submit(`/reactions/${type}/${uid}`, { emoji }, null, (result) => this.render(bar, result), trigger);
|
||||
await this.submit(`/reactions/${type}/${uid}`, { emoji }, null, (result) => this.render(bar, result));
|
||||
this.closeAllPalettes();
|
||||
}
|
||||
|
||||
|
||||
@@ -34,7 +34,6 @@ export class VoteManager extends OptimisticAction {
|
||||
() => this.render(action, { net: predictedNet, value: newValue }),
|
||||
() => this.render(action, { net: prevNet, value: prevValue }),
|
||||
(result) => this.render(action, result),
|
||||
button,
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
<button type="button" class="post-action-btn bookmark-btn{% if _bookmarked %} bookmarked{% endif %}" data-bookmark-type="{{ _type }}" data-bookmark-uid="{{ _uid }}" title="Save" aria-label="Save" aria-pressed="{% if _bookmarked %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>
|
||||
<span class="btn-spinner" aria-hidden="true"></span><span class="bookmark-icon">🔖</span> <span class="bookmark-label">{% if _bookmarked %}Saved{% else %}Save{% endif %}</span>
|
||||
<span class="bookmark-icon">🔖</span> <span class="bookmark-label">{% if _bookmarked %}Saved{% else %}Save{% endif %}</span>
|
||||
</button>
|
||||
|
||||
@@ -3,12 +3,12 @@
|
||||
<div class="comment-votes" role="group" aria-label="Comment votes">
|
||||
<form method="POST" action="/votes/comment/{{ item.comment['uid'] }}">
|
||||
<input type="hidden" name="value" value="1">
|
||||
<button type="submit" class="comment-vote-btn vote-up{% if item.my_vote == 1 %} voted{% endif %}" aria-label="Upvote" title="Upvote" aria-pressed="{% if item.my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span>+</button>
|
||||
<button type="submit" class="comment-vote-btn vote-up{% if item.my_vote == 1 %} voted{% endif %}" aria-label="Upvote" title="Upvote" aria-pressed="{% if item.my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>+</button>
|
||||
</form>
|
||||
<span class="comment-vote-count" data-vote-count="{{ item.comment['uid'] }}">{{ item.votes.up - item.votes.down }}</span>
|
||||
<form method="POST" action="/votes/comment/{{ item.comment['uid'] }}">
|
||||
<input type="hidden" name="value" value="-1">
|
||||
<button type="submit" class="comment-vote-btn vote-down{% if item.my_vote == -1 %} voted{% endif %}" aria-label="Downvote" title="Downvote" aria-pressed="{% if item.my_vote == -1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span>-</button>
|
||||
<button type="submit" class="comment-vote-btn vote-down{% if item.my_vote == -1 %} voted{% endif %}" aria-label="Downvote" title="Downvote" aria-pressed="{% if item.my_vote == -1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>-</button>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
@@ -25,11 +25,11 @@
|
||||
{% include "_attachment_display.html" %}
|
||||
{% endif %}
|
||||
<div class="comment-actions">
|
||||
<button type="button" class="comment-action-btn" data-action="reply"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span><span class="icon">💬</span><span class="label"> Reply</span></button>
|
||||
<button type="button" class="comment-action-btn" data-action="reply"{{ guest_disabled(user) }}><span class="icon">💬</span><span class="label"> Reply</span></button>
|
||||
{% if owns(item.comment, user) %}
|
||||
<button type="button" class="comment-action-btn" data-action="edit" data-edit-url="/comments/edit/{{ item.comment['uid'] }}"><span class="btn-spinner" aria-hidden="true"></span><span class="icon">✏️</span><span class="label"> Edit</span></button>
|
||||
<button type="button" class="comment-action-btn" data-action="edit" data-edit-url="/comments/edit/{{ item.comment['uid'] }}"><span class="icon">✏️</span><span class="label"> Edit</span></button>
|
||||
<form method="POST" action="/comments/delete/{{ item.comment['uid'] }}" class="inline-form comment-delete-form" data-comment-uid="{{ item.comment['uid'] }}">
|
||||
<button type="submit" class="comment-action-btn" data-confirm="Delete this comment?"><span class="btn-spinner" aria-hidden="true"></span><span class="icon">🗑️</span><span class="label"> Delete</span></button>
|
||||
<button type="submit" class="comment-action-btn" data-confirm="Delete this comment?"><span class="icon">🗑️</span><span class="label"> Delete</span></button>
|
||||
</form>
|
||||
{% endif %}
|
||||
{% set _type = "comment" %}{% set _uid = item.comment['uid'] %}{% set _reactions = item.reactions %}{% include "_reaction_bar.html" %}
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
max-size="{{ max_upload_size_mb() }}"
|
||||
max-files="{{ max_attachments_per_resource() }}"
|
||||
allowed-types="{{ allowed_file_types() }}"></dp-upload>
|
||||
<button type="submit" class="comment-form-submit"><span class="btn-spinner" aria-hidden="true"></span><span class="icon">📤</span><span class="label"> Post</span></button>
|
||||
<button type="submit" class="comment-form-submit"><span class="icon">📤</span><span class="label"> Post</span></button>
|
||||
</div>
|
||||
</form>
|
||||
{% else %}
|
||||
|
||||
@@ -4,7 +4,6 @@
|
||||
<div class="poll-options" role="group" aria-label="Poll options">
|
||||
{% for opt in _poll.options %}
|
||||
<button type="button" class="poll-option{% if _poll.my_choice == opt.uid %} chosen{% endif %}" data-option-uid="{{ opt.uid }}" aria-pressed="{% if _poll.my_choice == opt.uid %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>
|
||||
<span class="btn-spinner" aria-hidden="true"></span>
|
||||
<span class="poll-option-bar" style="--poll-pct: {{ opt.pct }}%;"></span>
|
||||
<span class="poll-option-label">{{ render_title(opt.label) }}</span>
|
||||
<span class="poll-option-meta">
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
<div class="post-votes" role="group" aria-label="Post votes">
|
||||
<form method="POST" action="/votes/post/{{ _uid }}" class="inline-form">
|
||||
<input type="hidden" name="value" value="-1">
|
||||
<button type="submit" class="post-action-btn vote-down{% if _my_vote == -1 %} voted{% endif %}" aria-label="Downvote" title="Downvote" aria-pressed="{% if _my_vote == -1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span>−</button>
|
||||
<button type="submit" class="post-action-btn vote-down{% if _my_vote == -1 %} voted{% endif %}" aria-label="Downvote" title="Downvote" aria-pressed="{% if _my_vote == -1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>−</button>
|
||||
</form>
|
||||
<span class="post-vote-count" data-vote-count="{{ _uid }}">{{ _count }}</span>
|
||||
<form method="POST" action="/votes/post/{{ _uid }}" class="inline-form">
|
||||
<input type="hidden" name="value" value="1">
|
||||
<button type="submit" class="post-action-btn vote-up{% if _my_vote == 1 %} voted{% endif %}" aria-label="Upvote" title="Upvote" aria-pressed="{% if _my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span>+</button>
|
||||
<button type="submit" class="post-action-btn vote-up{% if _my_vote == 1 %} voted{% endif %}" aria-label="Upvote" title="Upvote" aria-pressed="{% if _my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}>+</button>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
<form method="POST" action="/votes/{{ _type }}/{{ _uid }}" class="inline-form"{% if _stop %} data-stop-propagation{% endif %}>
|
||||
<input type="hidden" name="value" value="1">
|
||||
<button type="submit" class="{{ _btn_class }} vote-star{% if _my_vote == 1 %} voted{% endif %}" aria-label="Star" aria-pressed="{% if _my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="btn-spinner" aria-hidden="true"></span><span class="vote-count-value" data-vote-count="{{ _uid }}">{{ _count }}</span></button>
|
||||
<button type="submit" class="{{ _btn_class }} vote-star{% if _my_vote == 1 %} voted{% endif %}" aria-label="Star" aria-pressed="{% if _my_vote == 1 %}true{% else %}false{% endif %}"{{ guest_disabled(user) }}><span class="vote-count-value" data-vote-count="{{ _uid }}">{{ _count }}</span></button>
|
||||
</form>
|
||||
|
||||
@@ -177,3 +177,23 @@ def test_prestige_below_level_returns_400(app_server, seeded_db):
|
||||
_reset_farm(name)
|
||||
response = session.post(f"{BASE_URL}/game/prestige", headers=JSON)
|
||||
assert response.status_code == 400
|
||||
|
||||
|
||||
def test_rate_limit_blocks_excess_requests(app_server, seeded_db):
|
||||
session, name = _signup()
|
||||
_reset_farm(name)
|
||||
responses = []
|
||||
for _ in range(31):
|
||||
responses.append(
|
||||
session.post(f"{BASE_URL}/game/buy-plot", headers=JSON)
|
||||
)
|
||||
success_count = sum(1 for r in responses[:30] if r.status_code != 429)
|
||||
assert success_count >= 1, "expected at least one successful request"
|
||||
assert responses[-1].status_code == 429, f"expected 429 on 31st request, got {responses[-1].status_code}"
|
||||
assert "Rate limit exceeded" in responses[-1].json().get("detail", "")
|
||||
# Verify the rate limit log stored entries for the test user
|
||||
from devplacepy.database import get_table
|
||||
user = get_table("users").find_one(username=name)
|
||||
table = get_table("rate_limit_log")
|
||||
entries = list(table.find(user_uid=user["uid"]))
|
||||
assert len(entries) >= 2, f"expected rate log entries, got {len(entries)}"
|
||||
|
||||
@@ -212,3 +212,28 @@ def test_steal_cooldown_blocks_second_raid(app_server, seeded_db):
|
||||
f"{BASE_URL}/game/farm/{owner}/steal", data={"slot": 0}, headers=JSON
|
||||
)
|
||||
assert second.status_code == 400
|
||||
|
||||
|
||||
def test_harvest_plant_cooldown_blocks_rapid_replant(app_server, seeded_db):
|
||||
session, name = _signup()
|
||||
_reset_farm(name)
|
||||
# Plant and ripen a crop on slot 0
|
||||
plant = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 0, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert plant.status_code == 200
|
||||
_ripen_owner_plot(name)
|
||||
# Harvest it — this sets a 5-second cooldown on the plot
|
||||
harvest = session.post(f"{BASE_URL}/game/harvest", data={"slot": 0}, headers=JSON)
|
||||
assert harvest.status_code == 200
|
||||
# Immediately replant on the same slot — must fail
|
||||
replant = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 0, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert replant.status_code == 400
|
||||
assert "cooldown" in replant.text.lower()
|
||||
# A different slot should still work
|
||||
other = session.post(
|
||||
f"{BASE_URL}/game/plant", data={"slot": 1, "crop": "shell"}, headers=JSON
|
||||
)
|
||||
assert other.status_code == 200
|
||||
|
||||
@@ -119,3 +119,23 @@ def test_game_actions_registered_with_correct_auth():
|
||||
def test_game_read_actions_are_read_only():
|
||||
for name in ("game_state", "game_leaderboard", "game_view_farm"):
|
||||
assert BY_NAME[name].is_read_only is True
|
||||
|
||||
|
||||
def test_all_game_post_actions_require_confirm():
|
||||
mutating_game_actions = {
|
||||
"game_plant",
|
||||
"game_harvest",
|
||||
"game_buy_plot",
|
||||
"game_upgrade_ci",
|
||||
"game_water",
|
||||
"game_steal",
|
||||
"game_fertilize",
|
||||
"game_daily",
|
||||
"game_upgrade_perk",
|
||||
"game_claim_quest",
|
||||
"game_prestige",
|
||||
"game_upgrade_legacy",
|
||||
}
|
||||
for name in mutating_game_actions:
|
||||
assert name in BY_NAME, f"{name} missing from catalog"
|
||||
assert name in CONFIRM_REQUIRED, f"{name} missing from CONFIRM_REQUIRED"
|
||||
|
||||
Reference in New Issue
Block a user