INNER CODE UNIT · TypeScript

adminImpl

colyseus/colyseus · packages/admin/src-backend/index.ts:446

function adminImpl(opts: AdminOptions) {
  // In production, refuse to boot without a JWT secret — admin sessions
  // would otherwise be unsignable (and the failure would surface only
  // at the first login attempt, not at startup). Devs without an env
  // var get a one-time warning so the workflow still works locally.
  assertJwtSecretConfigured();

  const ctx = buildContext(opts);

  // Resolve rate limiters. Defaults are tuned for "single bad actor"
  // protection: 10 login attempts per minute per (ip, email) and ~1
  // bootstrap per minute per ip. Operators can pass `false` to disable
  // or a custom `RateLimiter` (Redis-backed, etc.).
  const loginLimiter = resolveLimiter(opts.rateLimit?.login, {
    capacity: 10, refillPerSec: 1 / 6, retryAfterSec: 6,
  });
  const bootstrapLimiter = resolveLimiter(opts.rateLimit?.bootstrap, {
    capacity: 5, refillPerSec: 1 / 60, retryAfterSec: 60,

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…