Rate-limit anonymous ticket creation; reap unpaid guest rows on cancel #38
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
POST /events/api/v1/tickets/{event_id}is anonymous by design (guest checkout, #36) and has no rate limit: any caller can mint invoices and Stripe Checkout Sessions against an event (up toquantity=10per call), creating unpaid rows and Stripe sessions in the organizer's account. Unpaid rows are only purged after 24 h (crud.purge_unpaid_tickets), so a burst can also exhaust visible capacity for a day if the client counts unpaid rows.Proposal
Retry-After.?checkout=cancelledreturn: the webapp could call a newDELETE /api/v1/tickets/pending/{payment_hash}(anonymous, only deletes unpaid rows for that hash) so an abandoned checkout frees the seats immediately instead of at the 24 h sweep.Related: #29 (identity limits on free claims).