check / check (push) Successful in 3m3s
POST / had no limit, so the signing key could be guessed at no cost. It is now limited to LoginAttemptsPerMinute (5) attempts per minute per client by a new RateLimit middleware on github.com/go-chi/httprate. It counts by the address the ClientIP middleware resolved through trusted_proxies, an IPv6 client by its /64, and answers an attempt over the limit with 429 and Retry-After. It runs after the body-size and CSRF checks, so every attempt that reaches the key comparison is counted. The image routes can reuse it. README states the limit; TODO narrows the per-IP item to the image routes. Model: opus-5-5