feat(api): API keys + Redis rate limiting + usage stats
Add an optional API-key layer to the public read-only API. Keys grant higher per-minute rate limits and attribute usage; anonymous callers are still allowed at a lower IP-based budget. - migration 0008_api_key: api_key table (sha256 hash only, plaintext shown once) - apikey pkg: key generation + hashing - ratelimit pkg: Redis fixed-window limiter + per-key usage counters; fails open - public API middleware: X-API-Key / Bearer auth, X-RateLimit-* headers, 429+Retry-After - admin: issue/list/revoke keys + usage view (API + UI tab) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -123,4 +123,18 @@ export const api = {
|
||||
method: "POST",
|
||||
body: JSON.stringify({ note }),
|
||||
}),
|
||||
listApiKeys: () =>
|
||||
request<{ items: import("./types").ApiKey[] }>("/keys"),
|
||||
createApiKey: (body: {
|
||||
name: string;
|
||||
owner_email?: string;
|
||||
tier?: string;
|
||||
rate_limit_per_min?: number;
|
||||
}) =>
|
||||
request<{ key: string; item: import("./types").ApiKey; warning: string }>(
|
||||
"/keys",
|
||||
{ method: "POST", body: JSON.stringify(body) },
|
||||
),
|
||||
revokeApiKey: (id: string) =>
|
||||
request<{ status: string }>(`/keys/${id}`, { method: "DELETE" }),
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user