6c3999a06769cc9517ea9281cf3eeae4d2392656
handleEmailOTPStart minted and mailed a code on every call, so an authenticated caller could drive unbounded mail to any address they typed — an email-bomb primitive against arbitrary mailboxes. Add a separate otpLimiter (its own sync.Once and map, distinct from the wake limiter) and throttle each send on two keys before anything is minted: the caller (user:<id>) and the recipient (email:<lower>). A refused send mints no code and mails nothing; both cooldowns are recorded only after delivery succeeds, mirroring the wake path so a failed mint or delivery never consumes the throttle. The two-key design stops both one account fanning out across addresses and many accounts converging on one mailbox.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%