fix(backend): rate-limit and cap report ingest, drop wildcard CORS (closes #20)
check / check (push) Successful in 58s
check / check (push) Successful in 58s
POST /api/v1/reports stays unauthenticated but is bounded. Each client address, as the trusted-proxy logic resolves it, may send REPORTS_PER_MINUTE reports a minute (default 60, all at once if it likes), using golang.org/x/time/rate; past that it gets 429 with Retry-After. Buckets that have refilled are dropped once a minute, so idle addresses do not pile up. reportbuf refuses a report that would take the report files past DATA_DIR_MAX_BYTES (default 1 GiB) with ErrFull, answered with 507; the count starts from the files already in DATA_DIR, and reports not yet written count at their uncompressed size. CORS adds nothing unless CORS_ALLOWED_ORIGINS lists origins. A limit that is not a positive number stops the server from starting. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,15 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: bounded the report endpoint (issue #20): `POST /api/v1/reports`
|
||||
still needs no credentials, but each client address, as resolved through
|
||||
`TRUSTED_PROXIES`, may send `REPORTS_PER_MINUTE` (default 60) reports a minute
|
||||
and past that gets 429 with `Retry-After`; the report files in `DATA_DIR`,
|
||||
counted from start with those already there, may total at most
|
||||
`DATA_DIR_MAX_BYTES` (default 1 GiB), past which reports get 507; and the
|
||||
wildcard CORS is gone: no CORS headers unless `CORS_ALLOWED_ORIGINS` lists
|
||||
origins. Deleting report files frees room only at the next start; pruning is
|
||||
issue #54
|
||||
- 2026-09-28: unified the gate (issue #16): the root `make check` covers the Go
|
||||
backend as well as the frontend, and the pre-commit hook with it; the backend
|
||||
moved onto scripts-to-rule-them-all (`backend/script/*`, `backend/Makefile` as
|
||||
|
||||
Reference in New Issue
Block a user