feat(sprint4): completar optimizador heuristico concurrente, integracion Spring Boot, correccion de login y fixes visuales

This commit is contained in:
Carlos Tello
2026-09-05 02:20:47 -03:00
parent dd93b8c07a
commit 69d545b718
17 changed files with 1021 additions and 91 deletions
+10 -4
View File
@@ -41,8 +41,12 @@ class SecurityFilterChain:
"""Ejecuta los filtros previos al enrutamiento del controlador."""
path = request.path
# 1. Rate Limiting Filter
# 1. Rate Limiting Filter (solo para peticiones POST de autenticación sensible)
if path in self._rate_limits:
# Peticiones GET para cargar la interfaz web NO consumen intentos de fuerza bruta
if request.method != 'POST':
return
max_req, window = self._rate_limits[path]
client_ip = self._get_client_ip()
now = time.time()
@@ -52,16 +56,18 @@ class SecurityFilterChain:
timestamps = [t for t in timestamps if now - t < window]
if len(timestamps) >= max_req:
retry_after = int(window - (now - timestamps[0]))
retry_after = max(1, int(window - (now - timestamps[0])))
if path.startswith('/api/'):
return jsonify({
'error': 'TooManyRequests',
'message': f'Límite de peticiones excedido. Reintente en {retry_after} segundos.'
}), 429
# Para la web, renderizar vista o respuesta legible
return Response(
f"Demasiados intentos. Por favor espere {retry_after} segundos antes de volver a intentar.",
f"Demasiados intentos de autenticación desde su dirección IP. Por favor espere {retry_after} segundos antes de volver a intentar.",
status=429,
mimetype='text/plain'
mimetype='text/plain; charset=utf-8'
)
timestamps.append(now)