API: rate limiting #39

closed cmc opened this on 2026-08-27 03:47 UTC

Discussion

cmc 2026-08-27 03:47 UTC

There is no rate limiting on the HTTP surface at all. internal/sshd/ratelimit.go throttles per-IP SSH auth failures; nothing equivalent exists for httpd, so /api/v1/cmd is unmetered — every command in the registry, including writes, at whatever rate a caller manages.

Fine while the instance has one user and the API is off. It gates two things: enabling the API in production (#37), and open registration (#28), and a mobile client retrying on a flaky network is exactly the caller that will find the missing limit.

Wants per-token and per-IP limits, a distinct budget for writes, and 429 with Retry-After so a client can back off correctly rather than hammering.

closed by commit 7953e78178 by cmc: httpd: rate limit the JSON API

2026-08-27 04:01 UTC