I wrote 731 comment lines on this branch against 4,530 lines of code — 14%, where the rest of the repo runs at 1.8%. CLAUDE.md asks for code that reads like its surroundings, and this did not. Removed by genre rather than by taste: - restating the code, e.g. "JS getUTCDay() numbering: Sunday = 0" above the map that literally shows it, and a docblock on startOfWeek explaining that it returns the start of the week; - narrating history — "this used to rebuild the whole map", "left the bar recording forever" — which the commit message and git blame already carry; - saying the same thing in several places: the "cannot record is not a denied microphone" reason appeared three times in one file, and the "aborting stops a per-minute metered call" reason across three files. Each now lives once, where the behaviour it explains lives; - defending decisions nobody would question, like why toLatinDigits is its own module; - over-explaining defensive branches, three separate comments to distinguish null from missing-kind from unrecognised-kind. What stays is what the code cannot say: the patient-right convention in toFdi, whose failure mode is a valid code for the wrong tooth; the "this"-vs-"next" week anchoring; StrictMode re-arming mountedRef; Safari accepting no mimeType hint; and the invariants whose violation already cost a bug — the body parser's middleware ordering and the dispatch panel's auto-fill rules. Comments only. The diff contains no non-comment line. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
30 lines
1.2 KiB
TypeScript
30 lines
1.2 KiB
TypeScript
import { HttpStatus, Injectable } from '@nestjs/common';
|
|
import { ThrottlerGuard } from '@nestjs/throttler';
|
|
import { AppException, ErrorCode } from '../../common/errors';
|
|
|
|
/**
|
|
* Rate limits voice extraction per user, not per IP: the default tracker keys on `req.ip`,
|
|
* which behind nginx means the whole deployment shares one bucket unless `trust proxy` is
|
|
* set, and one clinic could then lock out every other.
|
|
*/
|
|
@Injectable()
|
|
export class VoiceThrottlerGuard extends ThrottlerGuard {
|
|
protected getTracker(req: Record<string, unknown>): Promise<string> {
|
|
const user = req?.user as { id?: unknown } | undefined;
|
|
if (typeof user?.id === 'string' && user.id) {
|
|
return Promise.resolve(`voice:user:${user.id}`);
|
|
}
|
|
// Unauthenticated requests never reach here, but fall back rather than share a bucket.
|
|
const ip = typeof req?.ip === 'string' ? req.ip : 'unknown';
|
|
return Promise.resolve(`voice:ip:${ip}`);
|
|
}
|
|
|
|
/** Without this, ThrottlerException surfaces as INTERNAL_ERROR — there is no 429 fallback. */
|
|
protected throwThrottlingException(): Promise<void> {
|
|
throw new AppException(
|
|
ErrorCode.VOICE_RATE_LIMITED,
|
|
HttpStatus.TOO_MANY_REQUESTS,
|
|
);
|
|
}
|
|
}
|