Current state with latest updates

This commit is contained in:
2026-08-23 13:28:34 +02:00
parent 5af95f6533
commit f52879edbb
74 changed files with 5174 additions and 960 deletions
+47
View File
@@ -87,6 +87,21 @@ class AppServiceProvider extends ServiceProvider
$app->make(NullSubjectDetector::class),
]);
});
// Override Scout's default Meilisearch client binding: Scout registers it
// with no HTTP timeout, so a slow/overloaded Meilisearch leaves PHP-FPM
// workers blocked forever in curl_exec(), draining the whole pool under
// a search traffic spike. Fail fast instead.
$this->app->singleton(\Meilisearch\Client::class, function ($app) {
$config = $app['config']->get('scout.meilisearch');
$httpClient = new \GuzzleHttp\Client([
'connect_timeout' => 2,
'timeout' => 5,
]);
return new \Meilisearch\Client($config['host'], $config['key'], $httpClient);
});
}
/**
@@ -111,6 +126,8 @@ class AppServiceProvider extends ServiceProvider
$this->configureUploadRateLimiters();
$this->configureMessagingRateLimiters();
$this->configureDownloadRateLimiter();
$this->configureSearchRateLimiter();
$this->configureVectorSearchRateLimiter();
$this->configureArtworkRateLimiters();
$this->configureNovaCardRateLimiters();
$this->configureReactionRateLimiters();
@@ -468,6 +485,36 @@ class AppServiceProvider extends ServiceProvider
});
}
private function configureSearchRateLimiter(): void
{
RateLimiter::for('search', function (Request $request): array {
$userId = $request->user()?->id;
// Search fans out to Meilisearch + DB queries per request, so IP
// limits are kept tight to blunt scripted floods of /search traffic.
return [
Limit::perMinute(20)->by('search:user:' . ($userId ?? 'guest')),
Limit::perMinute(30)->by('search:ip:' . $request->ip()),
];
});
}
private function configureVectorSearchRateLimiter(): void
{
RateLimiter::for('vector-search', function (Request $request): array {
$userId = $request->user()?->id;
// Each hit here can trigger synchronous outbound HTTP to the vision
// vector gateway (image download + similarity search), so keep the
// per-IP allowance tight — unlike cached list endpoints, a flood of
// distinct artwork IDs can't be absorbed by cache alone.
return [
Limit::perMinute(30)->by('vector-search:user:' . ($userId ?? 'guest')),
Limit::perMinute(20)->by('vector-search:ip:' . $request->ip()),
];
});
}
private function configureArtworkRateLimiters(): void
{
RateLimiter::for('artwork-awards', function (Request $request): array {