诚实性修复: API限流Retry-After(wait=60s)+断言 / purge定时接线(04:00 cron+actor+测试) / Channel表单校验(ref+rules+validate) / README PG数字513

This commit is contained in:
seagull
2026-09-12 02:20:50 +08:00
parent b3f3095d53
commit 67540e8d30
40 changed files with 1805 additions and 31 deletions
+5
View File
@@ -42,6 +42,11 @@ class APIKeyAuthentication(authentication.BaseAuthentication):
if not key_obj.verify_key(raw_key):
raise exceptions.AuthenticationFailed("API Key 签名无效")
# P0-5:把纸面的 rate_limit 接进认证链(分钟窗口,超限 429)。
from apps.core.ratelimit import check_apikey_rate_limit
check_apikey_rate_limit(key_obj.prefix, key_obj.rate_limit)
# 记录调用时间并绑定 tenant
key_obj.last_used_at = timezone.now()
key_obj.save(update_fields=["last_used_at"])