configureRateLimiting(); // Belt-and-suspenders alongside bootstrap/app.php's trustProxies(): // that already makes url()/asset() respect the proxy's // X-Forwarded-Proto, but if that header is ever missing or a proxy // is misconfigured, this still forces https:// asset/route URLs on // any environment whose APP_URL is itself https — so a plain-http // request never causes a mixed-content-blocked asset again. if (str(config('app.url'))->startsWith('https://')) { URL::forceScheme('https'); } } /** * Named api/* rate limiters (T6.1, domain.md §8) — read-only catalog/ * routing endpoints get a looser limit than the write-heavy booking/ * payment endpoints; auth/token issuance and the inbound KBZ webhook * each get their own tighter limiter. */ private function configureRateLimiting(): void { RateLimiter::for('api-read', function (Request $request) { return Limit::perMinute(120)->by($request->user()?->id ?: $request->ip()); }); RateLimiter::for('api-write', function (Request $request) { return Limit::perMinute(20)->by($request->user()?->id ?: $request->ip()); }); RateLimiter::for('api-auth', function (Request $request) { return Limit::perMinute(10)->by($request->ip()); }); RateLimiter::for('api-webhooks', function (Request $request) { return Limit::perMinute(30)->by($request->ip()); }); } }