INNER CODE UNIT · TypeScript
adminImpl
colyseus/colyseus · packages/admin/src-backend/index.ts:446
function adminImpl(opts: AdminOptions) {
// In production, refuse to boot without a JWT secret — admin sessions
// would otherwise be unsignable (and the failure would surface only
// at the first login attempt, not at startup). Devs without an env
// var get a one-time warning so the workflow still works locally.
assertJwtSecretConfigured();
const ctx = buildContext(opts);
// Resolve rate limiters. Defaults are tuned for "single bad actor"
// protection: 10 login attempts per minute per (ip, email) and ~1
// bootstrap per minute per ip. Operators can pass `false` to disable
// or a custom `RateLimiter` (Redis-backed, etc.).
const loginLimiter = resolveLimiter(opts.rateLimit?.login, {
capacity: 10, refillPerSec: 1 / 6, retryAfterSec: 6,
});
const bootstrapLimiter = resolveLimiter(opts.rateLimit?.bootstrap, {
capacity: 5, refillPerSec: 1 / 60, retryAfterSec: 60,