Skip to content

Release: v0.2.3 - #180

Merged
themightychris merged 6 commits into
mainfrom
develop
Sep 17, 2026
Merged

themightychris merged 6 commits into
mainfrom
develop

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Stops the site-wide 429s seen right after cutover: the rate limiter now counts only /api requests, treats GET /api/auth/me as an ordinary read, and sees the signed-in session before it decides which bucket to use.

Improvements

themightychris and others added 6 commits September 17, 2026 18:42
…points

Only /api/** is counted; the SPA shell, assets and thumbnails never are.
Credential endpoints get their own per-IP cap; session reads such as
GET /api/auth/me are ordinary reads. Per-IP caps are generous because
production's load balancer does not yet preserve client addresses, so
every visitor currently shares one bucket (cfp-live-cluster #201).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LFyA5poHwrhAktrnsKrUiQ
Minutes after cutover the site was returning 429s to everyone. The
onRequest hook counted every asset and SPA request against the 60/min
read cap (a page load is dozens), GET /api/auth/me sat in the 10/min
/api/auth bucket alongside login, and the NodeBalancer hides client
addresses so all of that was one shared bucket.

Skip non-/api paths, classify credential endpoints explicitly, and put
the caps in an exported table the tests assert against. Existing tests
that issued 60 requests now prime the bucket instead.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LFyA5poHwrhAktrnsKrUiQ
All three plugins use onRequest hooks, which run in registration order,
so rate-limit and idempotency saw request.session unset and keyed every
signed-in request by IP. The existing test only passed because /me used
to fall into a different bucket.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LFyA5poHwrhAktrnsKrUiQ
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LFyA5poHwrhAktrnsKrUiQ
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LFyA5poHwrhAktrnsKrUiQ
fix(api): scope the rate limiter to /api and stop the post-cutover 429 storm
@github-actions

Copy link
Copy Markdown
Author

Changelog

- fix(api): scope the rate limiter to /api and stop the post-cutover 429 storm [#179] @themightychris

@themightychris
themightychris merged commit ae7ff3a into main Sep 17, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant