From 5ffce86768e6cd9cdbf09fda1037ea41db347c1c Mon Sep 17 00:00:00 2001 From: erik-krogh Date: Thu, 10 Aug 2023 13:40:17 +0200 Subject: [PATCH] change the defaults in the qhelp for missing-rate-limit to something more reasonable --- .../src/Security/CWE-770/examples/MissingRateLimitingGood.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/javascript/ql/src/Security/CWE-770/examples/MissingRateLimitingGood.js b/javascript/ql/src/Security/CWE-770/examples/MissingRateLimitingGood.js index 72bb25eab16f..1adc08ae39c1 100644 --- a/javascript/ql/src/Security/CWE-770/examples/MissingRateLimitingGood.js +++ b/javascript/ql/src/Security/CWE-770/examples/MissingRateLimitingGood.js @@ -4,8 +4,8 @@ var app = express(); // set up rate limiter: maximum of five requests per minute var RateLimit = require('express-rate-limit'); var limiter = RateLimit({ - windowMs: 1*60*1000, // 1 minute - max: 5 + windowMs: 15 * 60 * 1000, // 15 minutes + max: 100, // max 100 requests per windowMs }); // apply rate limiter to all requests