Skip to content

Qa/rate limit e2e and degraded agent notice - #1

Merged
muthanii merged 7 commits into
mainfrom
qa/rate-limit-e2e-and-degraded-agent-notice
Aug 2, 2026
Merged

muthanii merged 7 commits into
mainfrom
qa/rate-limit-e2e-and-degraded-agent-notice

Conversation

@muthanii

@muthanii muthanii commented Aug 2, 2026

Copy link
Copy Markdown
Owner

No description provided.

muthanii and others added 7 commits August 1, 2026 17:35
…able

clientIpFromRequest falls back to the literal "unknown" when no proxy sets
x-forwarded-for, so every local caller shares one bucket. The e2e suite
self-seeds a board per spec across 4 workers, blew the 10/min boards.create
budget, and failed 8 of 18 specs on `POST /api/boards failed: 429` — taking
out the release gate CLAUDE.md §9 and §10 depend on.

enforceRateLimit now reads an optional RATE_LIMIT_<BUCKET> ceiling. Absent,
non-numeric, or non-positive values keep the route's own default, so a typo
cannot silently disable a limit, and production behaviour is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…d in chat

When an agent degrades, dispatch skips its turns behind an info log and the
board chat says nothing. Observed live: the agent went degraded after its
endpoint failed, then 11 more @mentions were dropped in silence while the
sender kept typing at it. The roster pill is real but small and collapsed;
the chat is where the conversation is, and §7 forbids the silent refusal.

Announces the transition INTO degraded, so one outage costs one message
rather than one per dropped mention — the same restraint the rate-limit
notice in turns.ts already applies.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…er set

buildProviders() returns [] when no OAuth keys are configured, which is the
documented default ("providers are optional"). Auth.js then renders its
built-in sign-in page with an empty provider list: a bare white card, in the
product's light theme, with no text and no way back. The landing page linked
straight to it, so one of the only two CTAs a first-time visitor sees led
nowhere. Confirmed it is specifically the zero-provider case — configuring one
provider makes the built-in page render normally.

Replaces it with /signin (pages.signIn). With providers it lists them and
hands off to the real OAuth flow; with none it says so and offers the guest
path, which already works and is what the zero-setup principle points at. The
landing affordance is now conditional on a provider existing, so nothing
offers a sign-in that cannot happen.

callbackUrl arrives from the query string, so safeCallbackUrl keeps the
redirect same-origin. A leading "/" is not sufficient on its own: browsers
read "//evil.example" and "/\evil.example" as protocol-relative, so those are
rejected too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…irect

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…anded

CI has never passed. All 7 runs died at step 3, pnpm/action-setup@v4, before
install ever ran — so typecheck, lint, test and build have never executed on
GitHub even once.

action-setup@v4 throws when its `version` input disagrees with package.json's
packageManager pin:

  if (version && packageManagerVersion && packageManagerVersion !== version)
    throw new Error("Multiple versions of pnpm specified: ...")

The workflow said `version: 9`, package.json says `pnpm@9.15.4`, and
"9.15.4" !== "9". Removing the input lets the action read the pin, which is
also the behaviour we want: CI resolves the exact pnpm the lockfile was
written with, and the version lives in one place.

Verified the rest of the job locally with the root .env hidden, since CI has
no .env and those steps had never run there: frozen-lockfile install is in
sync, typecheck clean across all 7 packages, lint clean, 466 tests pass, and
the web build succeeds on the workflow's own throwaway env.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@muthanii
muthanii merged commit e0fdd55 into main Aug 2, 2026
1 check passed
@muthanii
muthanii deleted the qa/rate-limit-e2e-and-degraded-agent-notice branch August 2, 2026 05:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant