Repository navigation
Qa/rate limit e2e and degraded agent notice - #1
Merged
Merged
Conversation
…able clientIpFromRequest falls back to the literal "unknown" when no proxy sets x-forwarded-for, so every local caller shares one bucket. The e2e suite self-seeds a board per spec across 4 workers, blew the 10/min boards.create budget, and failed 8 of 18 specs on `POST /api/boards failed: 429` — taking out the release gate CLAUDE.md §9 and §10 depend on. enforceRateLimit now reads an optional RATE_LIMIT_<BUCKET> ceiling. Absent, non-numeric, or non-positive values keep the route's own default, so a typo cannot silently disable a limit, and production behaviour is unchanged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…d in chat When an agent degrades, dispatch skips its turns behind an info log and the board chat says nothing. Observed live: the agent went degraded after its endpoint failed, then 11 more @mentions were dropped in silence while the sender kept typing at it. The roster pill is real but small and collapsed; the chat is where the conversation is, and §7 forbids the silent refusal. Announces the transition INTO degraded, so one outage costs one message rather than one per dropped mention — the same restraint the rate-limit notice in turns.ts already applies. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…er set
buildProviders() returns [] when no OAuth keys are configured, which is the
documented default ("providers are optional"). Auth.js then renders its
built-in sign-in page with an empty provider list: a bare white card, in the
product's light theme, with no text and no way back. The landing page linked
straight to it, so one of the only two CTAs a first-time visitor sees led
nowhere. Confirmed it is specifically the zero-provider case — configuring one
provider makes the built-in page render normally.
Replaces it with /signin (pages.signIn). With providers it lists them and
hands off to the real OAuth flow; with none it says so and offers the guest
path, which already works and is what the zero-setup principle points at. The
landing affordance is now conditional on a provider existing, so nothing
offers a sign-in that cannot happen.
callbackUrl arrives from the query string, so safeCallbackUrl keeps the
redirect same-origin. A leading "/" is not sufficient on its own: browsers
read "//evil.example" and "/\evil.example" as protocol-relative, so those are
rejected too.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…irect Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…anded
CI has never passed. All 7 runs died at step 3, pnpm/action-setup@v4, before
install ever ran — so typecheck, lint, test and build have never executed on
GitHub even once.
action-setup@v4 throws when its `version` input disagrees with package.json's
packageManager pin:
if (version && packageManagerVersion && packageManagerVersion !== version)
throw new Error("Multiple versions of pnpm specified: ...")
The workflow said `version: 9`, package.json says `pnpm@9.15.4`, and
"9.15.4" !== "9". Removing the input lets the action read the pin, which is
also the behaviour we want: CI resolves the exact pnpm the lockfile was
written with, and the version lives in one place.
Verified the rest of the job locally with the root .env hidden, since CI has
no .env and those steps had never run there: frozen-lockfile install is in
sync, typecheck clean across all 7 packages, lint clean, 466 tests pass, and
the web build succeeds on the workflow's own throwaway env.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.