Files
website/server/api/account/update-email.patch.ts
limes f7586648a5
Some checks failed
Build and Publish Docker Image / Build and Publish (amd64) (push) Has been cancelled
Build and Publish Docker Image / Build and Publish (arm64) (push) Has been cancelled
feat: bump ratelimits
2026-08-29 18:19:19 +02:00

39 lines
1.1 KiB
TypeScript

import { ClientError } from 'nice-grpc';
import { EmailUpdateSchema } from '~~/shared/api-types';
import type { ApiErrorCodes } from '~~/shared/errors';
const bucket = createRatelimitBucket({
id: 'update-email',
points: 10,
durationSec: 30 * 60, // 30 minutes
blockDurationSec: 1 * 60 * 60 // 1 hour
});
const errors: Record<string, ApiErrorCodes> = {
'INVALID_ARGUMENT: Must provide new email address': 'UNPARSABLE_ERROR',
'INVALID_ARGUMENT: Invalid email address': 'INVALID_EMAIL',
'INVALID_ARGUMENT: New email address must differ from current': 'EMAIL_UNCHANGED'
};
export default defineEventHandler(async (event): Promise<void> => {
await enforceRatelimit(event, bucket);
const body = await readZodBody(event, EmailUpdateSchema);
const auth = enforceLoggedIn(event);
const grpc = useApiGrpcWithToken(event, auth.token);
try {
await grpc.updateEmail({
email: body.email
});
} catch (error: unknown) {
if (error instanceof ClientError) {
const errorCode = errors[error.details];
if (errorCode) {
throw createApiError(errorCode);
}
}
throw error;
}
});