Repository navigation
feat: per-user rate limiting for chat API endpoints - #342
Righteous-81 wants to merge 5 commits into
Conversation
|
@Righteous-81 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
* app/config.py: the committed file was a base64 payload, not Python; restored with RATE_LIMIT_CHAT_DAILY kept. * migrations/versions/g1a2b3c4d5e6_add_rate_limit_table.py: importable (`sqlalchemy as sa`) and chained onto the current head `c2d3e4f5a6b7` so `flask db heads` stays a single head. * app/models/rate_limit.py: persistent counter model for the daily cap. * app/services/ratelimit.py: DB-backed daily cap helpers alongside the in-memory sliding window. * app/chat/api.py: apply the daily cap to message sends and report the remaining quota; app/templates/chat/index.html: fix the corrupted Jinja delimiters. * tests: assert the new migration head and the rate_limits upgrade/downgrade.
…oints Brings the branch up to date with main and keeps this PR's changes (including the rate-limit migration head assertion).
|
@AyinkxLab — CI fix pushed for this PR. Red before: Root cause: What I changed:
Verification: Local check on the merged tree ( New head: @AyinkxLab — could you approve the workflows / re-run CI when you get a chance? |
|
@AyinkxLab I've repaired the CI failures on this branch. Root causes, matching the failing jobs:
Verification, running exactly what the CI jobs run, on this branch merged with current One thing I cannot do from the fork: the workflow run for this head is parked in |
Overview
This PR adds per-user rate limiting to the chat API to protect message-send and stream endpoints from abuse and runaway costs. Limits are configurable via environment variables with sane defaults, enforced per authenticated user, tracked persistently, and surfaced in the chat UI so users see their remaining budget before they hit the cap. Exceeding a limit returns
429with aRetry-Afterheader.Related Issue
Changes
🚦 Rate Limiting Service
[ADD]
app/services/ratelimit.pyRetry-After.[MODIFY]
app/config.py[MODIFY]
.env.example[MODIFY]
docker-compose.yml🔌 Chat API Enforcement
app/chat/api.py429with aRetry-Afterheader when a user exceeds a limit.🖥️ UI Surfacing
[MODIFY]
app/static/js/chat.js429responses gracefully, showing retry timing instead of a generic error.[MODIFY]
app/templates/chat/index.html📚 Docs
docs/security.mdVerification Results
Retry-Afterapp/chat/api.pyviaapp/services/ratelimit.pyCloses #14