# 61 — Rate limiting on share links ## Goal Prevent token brute-forcing on `/s/`. ## Depends on - 31 ## Scope - IP + token-prefix bucket. Reject after N failed lookups per minute per IP. In-memory LRU is fine for one Node process; document switch to Redis if multi-process arrives. - Failed `resolveShareToken` calls increment the bucket; successful resolves do not. - Generic `lib/rate-limit.ts` so other endpoints can use the same primitive. ## Out of scope - Captcha. ## Acceptance criteria - [ ] 50 bad tokens from one IP in a minute returns 429 thereafter. - [ ] Legitimate access from another IP unaffected.