* fix: use userId as ratelimit identifier
Using raw api keys as identifiers is problematic because they are logged
and are accessible via Unkey's UI.
My first idea was to use the api key's primary key, which would solve
this just fine. But after looking at the implementation it seemed easier
to use the user's id, which is what most people are interested in
limiting, not the actual keys. Also the userId was already passed in the
requests context, which made it easier. Sean confirmed that ratelimiting
the user, not their keys made more sense, so here we are.
* Update rateLimitApiKey.ts
* Update rateLimitApiKey.ts
* Fix tests
* Fix tests
---------
Co-authored-by: Benny Joo <sldisek783@gmail.com>
Co-authored-by: Joe Au-Yeung <j.auyeung419@gmail.com>
* add delete to redis service
* auto lock + tests
* changes to autolock in api/book call
* remove log clutter
* add detection in api v1
* tpye changes
* throw error and add tests for API
* add response logic on locked + tests
* type response properly i hope?
* type fix
* add tests for counter not existing + redis errors
* remove IP - add sentry to track
* rename symbol
* fix type error
* fix tests
* remove sentry call spy
* fix type on sentry setUser call
---------
Co-authored-by: Alex van Andel <me@alexvanandel.com>
* set status code
* Add tests
* Update apps/api/v1/lib/helpers/rateLimitApiKey.test.ts
* Update apps/api/v1/lib/helpers/rateLimitApiKey.test.ts
---------
Co-authored-by: Keith Williams <keithwillcode@gmail.com>