@@ -77,15 +77,15 @@ export class AuthModule {
7777 // Rate limiters for different route types
7878 const authLimiter = rateLimit ( {
7979 windowMs : 60 * 1000 , // 1 minute
80- max : 20 , // 20 requests per minute for auth endpoints
80+ max : 200 , // 200 requests per minute for auth endpoints
8181 message : 'Too many authentication attempts' ,
8282 standardHeaders : true ,
8383 legacyHeaders : false ,
8484 } ) ;
8585
8686 const staticAssetLimiter = rateLimit ( {
8787 windowMs : 60 * 1000 , // 1 minute
88- max : 100 , // 100 requests per minute for static assets
88+ max : 500 , // 500 requests per minute for static assets
8989 message : 'Too many requests for static assets' ,
9090 standardHeaders : true ,
9191 legacyHeaders : false ,
@@ -96,10 +96,10 @@ export class AuthModule {
9696 provider : this . provider ,
9797 issuerUrl : new URL ( this . config . authServerUrl || this . config . baseUri ) ,
9898 tokenOptions : {
99- rateLimit : { windowMs : 5000 , limit : 100 }
99+ rateLimit : { windowMs : 5000 , limit : 300 } // 300 requests per 5 seconds
100100 } ,
101101 clientRegistrationOptions : {
102- rateLimit : { windowMs : 60000 , limit : 10 }
102+ rateLimit : { windowMs : 60000 , limit : 60 } // 60 requests per minute
103103 }
104104 } ) ) ;
105105
0 commit comments