Improve session privacy handling and cleanup logic

This commit is contained in:
thakares committed 2026-05-23 15:57:34 +05:30
1 parent 0b43530651
commit a8411ddaf4
4 files changed
+15 -26

No files matched your search

+1 -7
View File
@@ -20,13 +20,7 @@ pub async fn cleanup_loop(state: Arc<AppState>) {
// Evict stale rate-limiter entries to prevent unbounded HashMap growth.
{
let window_secs = {
if let Ok(config) = state.config.read() {
config.rate_limit_window_secs
} else {
10 // fallback default
}
};
let window_secs = state.get_config().rate_limit_window_secs;
let mut rl = state.rate_limiter.lock().await;
rl.evict_stale(window_secs);
}
+3 -12
View File
@@ -10,11 +10,8 @@ pub async fn handler(
// Rate limiting
{
let (limit, window_secs) = {
if let Ok(cfg) = state.config.read() {
(cfg.rate_limit_count, cfg.rate_limit_window_secs)
} else {
(5, 10)
}
let cfg = state.get_config();
(cfg.rate_limit_count, cfg.rate_limit_window_secs)
};
let mut rl = state.rate_limiter.lock().await;
if !rl.check(&payload.session_id, limit, window_secs) {
@@ -29,13 +26,7 @@ pub async fn handler(
}
}
let config = {
if let Ok(cfg) = state.config.read() {
cfg.clone()
} else {
crate::config::Config::default()
}
};
let config = state.get_config();
let conn = match state.db_pool.get() {
Ok(c) => c,
Err(e) => {
+1 -7
View File
@@ -8,13 +8,7 @@ pub async fn handler(
State(state): State<Arc<AppState>>,
Json(payload): Json<InitRequest>,
) -> Result<Json<InitResponse>, SessionError> {
let config = {
if let Ok(cfg) = state.config.read() {
cfg.clone()
} else {
crate::config::Config::default()
}
};
let config = state.get_config();
let conn = state.db_pool.get()?;
let resp = crate::session::create_session(&conn, &config, &payload.public_key)?;
Ok(Json(resp))
+10
View File
@@ -4,6 +4,16 @@ pub struct AppState {
pub config: std::sync::RwLock<crate::config::Config>,
}
impl AppState {
pub fn get_config(&self) -> crate::config::Config {
if let Ok(cfg) = self.config.read() {
cfg.clone()
} else {
crate::config::Config::default()
}
}
}
use crate::{crypto, fingerprint, storage, trust, vm};
use rusqlite::params;
use shared::protocol::{HeartbeatRequest, InitResponse};