Skip to content

feat(api): bound event list responses by size and time - #351

Draft
tsan88 wants to merge 1 commit into
buggregator:masterfrom
tsan88:feat/api-event-list-limits
Draft

feat(api): bound event list responses by size and time#351
tsan88 wants to merge 1 commit into
buggregator:masterfrom
tsan88:feat/api-event-list-limits

Conversation

@tsan88

@tsan88 tsan88 commented Sep 4, 2026

Copy link
Copy Markdown

/api/events and /api/events/preview returned every event stored for the requested type/project. Limit and Offset already existed in event.FindOptions, but the handlers never filled them in.

Measured on a production instance (≈40k events/day): a single /api/events/preview response for one project weighed 25.8 MB, which the frontend then filtered in the browser. That is the dominant cost of opening the UI.

Changes

  • Both endpoints accept limit, offset/page, from, to and window ("15m", "24h", "7d"; "all" or "0" opt out of the configured default). from/to take unix seconds or ISO 8601.
  • The response meta reports what was applied (limit, offset, returned, from, to), so a client can tell a truncated response from an exhausted one.
  • New ui config section: default_limit (1000), max_limit (5000), default_window (empty), also settable via UI_DEFAULT_LIMIT / UI_MAX_LIMIT / UI_DEFAULT_WINDOW.
  • RegisterAPI takes a ListLimits argument.

Defaults are deliberately conservative: a size cap only, no time window, so nothing disappears from an existing UI unless an operator asks for it. An unreadable default_window logs a warning and is ignored rather than failing startup.

On our instance the same request is now 189 KB with default_limit: 500 and default_window: 1h.

Testing

go vet ./..., go test ./... and go build pass. Added TestAPI_Events_Limits (default limit, max_limit ceiling, default window, window=all, explicit from/to) and TestParseWindow. Existing tests pass an empty ListLimits, which keeps the old "return everything" behaviour.

Note for maintainers: the frontend side of this (a period selector that sends window=) is buggregator/frontend#290, and it degrades gracefully against a server without this PR.

/api/events and /api/events/preview returned every event stored for the
requested type/project — FindOptions already had Limit and Offset, but the
handlers never filled them in. On a busy instance one preview request weighed
25.8 MB, and the frontend then filtered that in the browser.

Both endpoints now accept limit, offset/page, from, to and window (15m, 24h,
"7d"; "all" opts out of the configured default), and report what was applied in
the response meta so a client can tell a truncated response from an exhausted
one.

Defaults are deliberately conservative and non-breaking: 1000 events per
response, no time window. An operator can set ui.default_window (or
UI_DEFAULT_WINDOW) to also narrow lists by time.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant