Skip to content

fix(rate-limit): give each authenticated gateway subject its own API budget - #163

Merged
ttbombadil merged 1 commit into
mainfrom
fix/api-rate-limit-identity
Oct 3, 2026
Merged

ttbombadil merged 1 commit into
mainfrom
fix/api-rate-limit-identity

Conversation

@ttbombadil

Copy link
Copy Markdown
Collaborator

Purpose

R7 of the refactoring series (docs/UNOSIM_REFACTORING_OPL.md), audit finding P1.

Finding re-verified

The global /api/ limiter (300 requests per 15 minutes in production) used the default key req.ip. Behind the gateway, a course on campus NAT shares one public IP, so one class could exhaust one budget. The identity-based compile, simulation and tutor limiters already key by subject.

Change

apiRateLimitKey(req, trust) in server/rate-limit-policy.ts, used as the limiter's keyGenerator:

  • Gateway mode with a valid gateway identity (same getRequestAuthorization the routes use; requires the gateway secret): key subject:<subject>.
  • Gateway requests without a valid identity, and local mode: key ip:<ipKeyGenerator(req.ip)>. This is the library's IPv6-aware default.
  • Local mode stays on the IP because a local client can always get a fresh session cookie.

No new authentication path, no change to limits, exemptions or the trust contract.

Tests

  • RED → GREEN: tests/server/routes/api-rate-limit-key.test.ts, in the serialized HTTP group. Two subjects behind one IP get separate budgets; invalid gateway secrets share the IP budget; local mode stays per IP.
  • npm run check, check:docs, ESLint, unit 2710 passed, pre-push incl. Sonar quality gate PASSED.

🤖 Generated with Claude Code

…budget

Behind the gateway, a course often shares one public IP. The global API limit
of 300 requests per 15 minutes was keyed by IP and could throttle a whole class.
Authenticated gateway subjects now get their own budget; everything else stays
keyed by IP.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ttbombadil
ttbombadil merged commit 7a39d55 into main Oct 3, 2026
5 checks passed
@ttbombadil
ttbombadil deleted the fix/api-rate-limit-identity branch October 3, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant