Finalize rate limit for enrollment API
LEARNER-5166
This commit is contained in:
@@ -1,10 +1,3 @@
|
||||
"""
|
||||
Enrollment API helpers and settings
|
||||
"""
|
||||
from openedx.core.djangoapps.waffle_utils import (WaffleSwitch, WaffleSwitchNamespace)
|
||||
|
||||
WAFFLE_SWITCH_NAMESPACE = WaffleSwitchNamespace(name='enrollment_api_rate_limit')
|
||||
|
||||
USE_RATE_LIMIT_400_FOR_STAFF_FOR_ENROLLMENT_API = WaffleSwitch(WAFFLE_SWITCH_NAMESPACE, 'staff_rate_limit_400')
|
||||
USE_RATE_LIMIT_100_FOR_STAFF_FOR_ENROLLMENT_API = WaffleSwitch(WAFFLE_SWITCH_NAMESPACE, 'staff_rate_limit_100')
|
||||
USE_RATE_LIMIT_40_FOR_ENROLLMENT_API = WaffleSwitch(WAFFLE_SWITCH_NAMESPACE, 'rate_limit_40')
|
||||
|
||||
@@ -12,11 +12,6 @@ from django.utils.decorators import method_decorator
|
||||
from edx_rest_framework_extensions.authentication import JwtAuthentication
|
||||
from enrollment import api
|
||||
from enrollment.errors import CourseEnrollmentError, CourseEnrollmentExistsError, CourseModeNotFoundError
|
||||
from enrollment import (
|
||||
USE_RATE_LIMIT_100_FOR_STAFF_FOR_ENROLLMENT_API,
|
||||
USE_RATE_LIMIT_40_FOR_ENROLLMENT_API,
|
||||
USE_RATE_LIMIT_400_FOR_STAFF_FOR_ENROLLMENT_API,
|
||||
)
|
||||
from opaque_keys import InvalidKeyError
|
||||
from opaque_keys.edx.keys import CourseKey
|
||||
|
||||
@@ -81,34 +76,14 @@ class ApiKeyPermissionMixIn(object):
|
||||
|
||||
class EnrollmentUserThrottle(UserRateThrottle, ApiKeyPermissionMixIn):
|
||||
"""Limit the number of requests users can make to the enrollment API."""
|
||||
# TODO: After confirming that reducing the throttle is successful, remove
|
||||
# and clean up waffles. The rate limit has been increased over the course
|
||||
# of a few months to account for unnecessary calls from the ecommerce
|
||||
# service. These calls are no longer made and the plan is to set the
|
||||
# rate limit back to its original state. LEARNER-5148
|
||||
|
||||
# To see how the staff rate limit was selected, see https://github.com/edx/edx-platform/pull/18360
|
||||
THROTTLE_RATES = {
|
||||
'user': '40/minute',
|
||||
'staff': '2000/minute',
|
||||
'staff': '120/minute',
|
||||
}
|
||||
|
||||
def allow_request(self, request, view):
|
||||
if USE_RATE_LIMIT_400_FOR_STAFF_FOR_ENROLLMENT_API.is_enabled():
|
||||
self.THROTTLE_RATES = {
|
||||
'user': '40/minute',
|
||||
'staff': '400/minute',
|
||||
}
|
||||
elif USE_RATE_LIMIT_100_FOR_STAFF_FOR_ENROLLMENT_API.is_enabled():
|
||||
self.THROTTLE_RATES = {
|
||||
'user': '40/minute',
|
||||
'staff': '100/minute',
|
||||
}
|
||||
elif USE_RATE_LIMIT_40_FOR_ENROLLMENT_API.is_enabled():
|
||||
self.THROTTLE_RATES = {
|
||||
'user': '40/minute',
|
||||
'staff': '40/minute',
|
||||
}
|
||||
|
||||
# Use a special scope for staff to allow for a separate throttle rate
|
||||
user = request.user
|
||||
if user.is_authenticated and (user.is_staff or user.is_superuser):
|
||||
|
||||
Reference in New Issue
Block a user