feat(api): API keys + Redis rate limiting + usage stats
Add an optional API-key layer to the public read-only API. Keys grant higher per-minute rate limits and attribute usage; anonymous callers are still allowed at a lower IP-based budget. - migration 0008_api_key: api_key table (sha256 hash only, plaintext shown once) - apikey pkg: key generation + hashing - ratelimit pkg: Redis fixed-window limiter + per-key usage counters; fails open - public API middleware: X-API-Key / Bearer auth, X-RateLimit-* headers, 429+Retry-After - admin: issue/list/revoke keys + usage view (API + UI tab) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -137,6 +137,25 @@ export interface SubmissionDetail {
|
||||
existing_product?: ProductDetail;
|
||||
}
|
||||
|
||||
export interface ApiKeyUsage {
|
||||
total: number;
|
||||
today: number;
|
||||
last_used_at?: number | null;
|
||||
}
|
||||
|
||||
export interface ApiKey {
|
||||
id: string;
|
||||
name: string;
|
||||
key_prefix: string;
|
||||
owner_email: string | null;
|
||||
tier: string;
|
||||
rate_limit_per_min: number;
|
||||
revoked_at: string | null;
|
||||
created_by: string | null;
|
||||
created_at: string;
|
||||
usage: ApiKeyUsage;
|
||||
}
|
||||
|
||||
export const FIELD_LABELS: Record<string, string> = {
|
||||
name: "名称",
|
||||
gtin: "条码",
|
||||
|
||||
Reference in New Issue
Block a user