Fixes an XFF-spoofing bypass of the flyer rate limiter (leftmost entry is attacker-controlled, not proxy-verified) and adds a second rate-limit dimension keyed on the submitted email so spamming one address still gets blocked even if IP-based limiting is ever defeated. Also bounds the in-memory rate-limit Map via a call-count-triggered sweep. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LhY1QhDXGWfyhrxaJvfpNt |
||
|---|---|---|
| .. | ||
| route.ts | ||