Rate Limiting & Headers
v4Proteja login, endpoints sensíveis e integrações com MUCRM\engine\support\rate_limitere headers HTTP explícitos.
Rate limit do login API
Padrão: 5 tentativas / 2 minutos por IP. Configure em config/api/rate_limit.php:
config('api.rate_limit.max_attempts');rate_limiter manual
use MUCRM\engine\support\rate_limiter;
$limiter = new rate_limiter();
$key = 'api:settings:' . request()->ip();
if ($limiter->too_many_attempts($key, 30)) {
return json([
'success' => false,
'error' => 'Too many requests',
'retry_after' => $limiter->available_in($key),
], 429);
}
$limiter->hit($key, 60);| Método | Descrição |
|---|---|
| too_many_attempts($key, $max) | Verifica limite |
| hit($key, $seconds) | Incrementa contador |
| available_in($key) | Segundos até liberar |
| clear($key) | Zera contador |
Headers
Accept: application/json
Content-Type: application/json
Authorization: Bearer mcrm_...return post::where('featured', 1)->json(200, [
'X-Cache' => 'HIT',
'Access-Control-Allow-Origin' => '*',
]);
json($payload, 200, [
'Access-Control-Allow-Origin' => '*',
'Access-Control-Allow-Methods' => 'GET, POST, OPTIONS',
'Access-Control-Allow-Headers' => 'Content-Type, Authorization',
]);Allowlist (auth.allowed)
Rodada automaticamente em /api/*:
'allowed' => ['*'],
'allowed' => [
'203.0.113.10',
'meusite.com',
'https://app.exemplo.com',
],