Skip to content

Potential fix for code scanning alert no. 363: Missing rate limiting - #88

Closed
mmeerrkkaa wants to merge 1 commit into
masterfrom
alert-autofix-363
Closed

mmeerrkkaa wants to merge 1 commit into
masterfrom
alert-autofix-363

Conversation

@mmeerrkkaa

@mmeerrkkaa mmeerrkkaa commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Potential fix for https://github.com/blockmineJS/blockmine/security/code-scanning/363

Add explicit Express rate-limiting middleware to the expensive plugin installation endpoints, especially the ZIP upload route at line 404 (the flagged location).
Best fix: use express-rate-limit and apply a dedicated limiter to plugin install routes so authenticated users cannot spam heavy operations. This does not change existing business functionality; it only throttles request frequency.

In backend/src/api/routes/bots.js:

  1. Add an import for express-rate-limit.
  2. Define a limiter (for example 10 requests per 15 minutes per IP) near other route-level setup.
  3. Insert that limiter into the middleware chain for:
    • router.post('/:botId/plugins/install/zip', ...) (required for the alert)
    • and also router.post('/:botId/plugins/install/local', ...) (same expensive class, good single fix coverage).

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

Summary by Sourcery

Bug Fixes:

  • Add rate limiting to plugin installation endpoints to mitigate abuse of expensive operations and address the missing rate-limiting code scanning alert.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 58 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7e8f3613-93fa-4c23-abd8-fe63caee4bbc
📥 Commits

Reviewing files that changed from the base of the PR and between 04b9f78 and 872071c.

📒 Files selected for processing (1)
  • backend/src/api/routes/bots.js
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The PR introduces a shared express-rate-limit middleware for both plugin installation routes, limiting each IP to 10 attempts per 15 minutes while leaving the existing installation, authentication, and authorization flows intact.

Sequence diagram for rate-limited plugin installation

sequenceDiagram
    actor Client
    participant Express as ExpressRouter
    participant Limiter as pluginInstallRateLimiter
    participant Auth as authenticateUniversal
    participant Access as checkBotAccess
    participant Authorize as authorize
    participant Install as PluginInstallation

    Client->>Express: POST /:botId/plugins/install/local or /zip
    Express->>Limiter: rateLimit(req)
    alt 10 requests exceeded in 15 minutes per IP
        Limiter-->>Client: 429 error
    else request allowed
        Limiter->>Auth: authenticateUniversal(req, res, next)
        Auth->>Access: checkBotAccess(req, res, next)
        Access->>Authorize: authorize(plugin:install)
        Authorize->>Install: Execute installation
        Install-->>Client: Installation response
    end
Loading

File-Level Changes

Change Details Files
Add a shared per-IP rate limiter to expensive plugin installation endpoints.
  • Import and configure express-rate-limit with a 15-minute window and 10-request limit.
  • Return standard rate-limit headers and a localized error message when the limit is exceeded.
  • Apply the limiter before authentication and authorization on both local-path and ZIP upload installation routes.
backend/src/api/routes/bots.js

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@mmeerrkkaa
mmeerrkkaa marked this pull request as ready for review October 5, 2026 22:42

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 2 issues

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="backend/src/api/routes/bots.js" line_range="6" />
<code_context>
 const path = require('path');
 const fs = require('fs/promises');
 const fse = require('fs-extra');
+const rateLimit = require('express-rate-limit');
 const { botManager, pluginManager } = require('../../core/services');
 const UserService = require('../../core/UserService');
</code_context>
<issue_to_address>
**Backend fails to start**

When the backend loads `bots.js`, the module declares `rateLimit` twice, so Node throws a duplicate-identifier `SyntaxError` and the backend cannot start.

Remove the duplicate declaration or reuse the existing `rateLimit` declaration.
</issue_to_address>

### Comment 2
<location path="backend/src/api/routes/bots.js" line_range="402" />
<code_context>
+    message: { error: 'Слишком много запросов на установку плагинов. Попробуйте позже.' }
+});
+
+router.post('/:botId/plugins/install/local', pluginInstallRateLimiter, authenticateUniversal, checkBotAccess, authorize('plugin:install'), async (req, res) => {
     const { botId } = req.params;
     const { path } = req.body;
</code_context>
<issue_to_address>
**Unauthenticated requests block installs**

When unauthenticated requests share an IP with authorized users and use up the ten-request quota, `pluginInstallRateLimiter` counts requests before authentication and authorization checks, so legitimate users from that IP receive 429 responses for plugin installs.

Run the limiter after authentication and authorization checks on both install routes.

Also at `backend/src/api/routes/bots.js:396-400`, `backend/src/api/routes/bots.js:413`.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨

const path = require('path');
const fs = require('fs/promises');
const fse = require('fs-extra');
const rateLimit = require('express-rate-limit');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Critical · Backend fails to start

When the backend loads bots.js, the module declares rateLimit twice, so Node throws a duplicate-identifier SyntaxError and the backend cannot start.

Remove the duplicate declaration or reuse the existing rateLimit declaration.

Prompt for AI agents
In `backend/src/api/routes/bots.js` at line 6:

**Backend fails to start**

When the backend loads `bots.js`, the module declares `rateLimit` twice, so Node throws a duplicate-identifier `SyntaxError` and the backend cannot start.

Remove the duplicate declaration or reuse the existing `rateLimit` declaration.

message: { error: 'Слишком много запросов на установку плагинов. Попробуйте позже.' }
});

router.post('/:botId/plugins/install/local', pluginInstallRateLimiter, authenticateUniversal, checkBotAccess, authorize('plugin:install'), async (req, res) => {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium · Unauthenticated requests block installs

When unauthenticated requests share an IP with authorized users and use up the ten-request quota, pluginInstallRateLimiter counts requests before authentication and authorization checks, so legitimate users from that IP receive 429 responses for plugin installs.

Run the limiter after authentication and authorization checks on both install routes.

Also at backend/src/api/routes/bots.js:396-400, backend/src/api/routes/bots.js:413.

Prompt for AI agents
In `backend/src/api/routes/bots.js` at line 402:

**Unauthenticated requests block installs**

When unauthenticated requests share an IP with authorized users and use up the ten-request quota, `pluginInstallRateLimiter` counts requests before authentication and authorization checks, so legitimate users from that IP receive 429 responses for plugin installs.

Run the limiter after authentication and authorization checks on both install routes.

Also at `backend/src/api/routes/bots.js:396-400`, `backend/src/api/routes/bots.js:413`.

@mmeerrkkaa mmeerrkkaa closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant