Security
The form save API has a rate limit control
- 1 request in 2 seconds
- 5 requests for 1 minute
If any of the limit is exceeded, the user is banned for 5 minutes
User is defined as a collection of tanantId + formId + ip This means that different forms for different tenants have their own limitations.
The ban can be removed if the g-recaptcha-response parameter, received from Google reCAPTCHA v3, is sent to the request
Known issues that may be solved in the future
At the moment, query statistics are stored in memory. Which means that if there are several lambda functions, then there will be several statistics and the specified restrictions will work a little incorrectly.
If in one lambda the user was banned but the request got to another lambda function it will be executed successfully, this will continue until the user is banned in all functions.
To fix this, need to add storage in the database, for example DynamoDB