Site

Rate Limiting & Headers

v4

Proteja login, endpoints sensíveis e integrações com MUCRM\engine\support\rate_limitere headers HTTP explícitos.


Rate limit do login API

Padrão: 5 tentativas / 2 minutos por IP. Configure em config/api/rate_limit.php:

config('api.rate_limit.max_attempts');

rate_limiter manual

use MUCRM\engine\support\rate_limiter;

$limiter = new rate_limiter();
$key = 'api:settings:' . request()->ip();

if ($limiter->too_many_attempts($key, 30)) {
    return json([
        'success' => false,
        'error' => 'Too many requests',
        'retry_after' => $limiter->available_in($key),
    ], 429);
}

$limiter->hit($key, 60);
MétodoDescrição
too_many_attempts($key, $max)Verifica limite
hit($key, $seconds)Incrementa contador
available_in($key)Segundos até liberar
clear($key)Zera contador

Headers

Accept: application/json
Content-Type: application/json
Authorization: Bearer mcrm_...
return post::where('featured', 1)->json(200, [
    'X-Cache' => 'HIT',
    'Access-Control-Allow-Origin' => '*',
]);

json($payload, 200, [
    'Access-Control-Allow-Origin'  => '*',
    'Access-Control-Allow-Methods' => 'GET, POST, OPTIONS',
    'Access-Control-Allow-Headers' => 'Content-Type, Authorization',
]);

Allowlist (auth.allowed)

Rodada automaticamente em /api/*:

'allowed' => ['*'],

'allowed' => [
    '203.0.113.10',
    'meusite.com',
    'https://app.exemplo.com',
],