From 6696e6bd545bd88b38f47274710839d946995236 Mon Sep 17 00:00:00 2001 From: kjs Date: Fri, 14 Aug 2026 16:40:39 +0900 Subject: [PATCH] =?UTF-8?q?=EC=B1=84=ED=8C=85:=20=ED=86=A0=ED=81=B0=20?= =?UTF-8?q?=EA=B2=80=EC=A6=9D=EC=9D=84=20=EB=8F=84=EB=B0=B0=20=EC=A0=9C?= =?UTF-8?q?=ED=95=9C=EB=B3=B4=EB=8B=A4=20=EB=A8=BC=EC=A0=80=20=EC=88=98?= =?UTF-8?q?=ED=96=89?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 미인증 요청이 남의 닉네임 전송 쿨다운을 소모해 정당한 유저를 429로 막을 수 있던 순서 결함 수정. Co-Authored-By: Claude Fable 5 --- src/lib/chat.ts | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/src/lib/chat.ts b/src/lib/chat.ts index b2c0a66..3252b6f 100644 --- a/src/lib/chat.ts +++ b/src/lib/chat.ts @@ -49,9 +49,8 @@ export async function sendChat( ): Promise { const text = rawText.replace(/\s+/g, " ").trim().slice(0, CHAT_MAX_LEN); if (!text) return "empty"; - const now = Date.now(); - if (now - (lastSent.get(nickname) ?? 0) < MIN_INTERVAL_MS) return "too_fast"; + // 인증을 도배 제한보다 먼저 — 미인증 요청이 남의 닉네임 전송 쿨다운을 소모하지 못하도록 await ensureVillages(); const owner = await db.query( "SELECT 1 FROM villages WHERE nickname = $1 AND token = $2", @@ -59,6 +58,9 @@ export async function sendChat( ); if (owner.rowCount === 0) return "auth"; + const now = Date.now(); + if (now - (lastSent.get(nickname) ?? 0) < MIN_INTERVAL_MS) return "too_fast"; + await ensureChatTable(); const r = await db.query( "INSERT INTO chat_messages (nickname, text) VALUES ($1, $2) RETURNING id, extract(epoch from created_at) * 1000 AS at",