Repository navigation
fix(providers): don't silently enable rate-limit protection on PATCH unless persisted - #11302
Merged
diegosouzapw merged 1 commit intoAug 24, 2026
Conversation
…unless persisted (#11278) PUT /api/providers/[id] unconditionally called enableRateLimitProtection(id) whenever the request body included rateLimitOverrides, even null. Since EditConnectionModal.tsx sends rateLimitOverrides on every connection save regardless of whether the operator touched that section, saving any connection silently started queuing its requests through Bottleneck while the DB (rate_limit_protection column) and the dashboard toggle both still showed the feature off. Only (re)enable the in-memory limiter when updated.rateLimitProtection is actually true (mapped from the persisted DB row), and explicitly disable it otherwise so runtime state can never drift ahead of the DB.
diegosouzapw
deleted the
fix/11278-patch-ratelimit-protection-persisted
branch
August 25, 2026 02:36
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…unless persisted (diegosouzapw#11278) (diegosouzapw#11302) Validated on a 4-PR combined board: provider-patch-ratelimit-protection-11278 2/2 + 56/56 sibling suites, typecheck:core clean, gates within baseline. PUT /api/providers/[id] can no longer silently enable rate-limit protection just because EditConnectionModal sends rateLimitOverrides on every save — the runtime toggle now strictly follows the persisted DB row. Closes diegosouzapw#11278.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PUT /api/providers/[id]unconditionally calledenableRateLimitProtection(id)whenever the request body includedrateLimitOverrides— evennull.EditConnectionModal.tsxsendsrateLimitOverrideson every connection save regardless of whether the operator touched that section, so saving any connection silently started queuing its requests through Bottleneck while the DB (rate_limit_protectioncolumn) and the dashboard toggle both still showed the feature off.updated.rateLimitProtection— mapped from the persisted DB row — is actuallytrue; otherwise explicitly calldisableRateLimitProtection(id)so runtime state can never drift ahead of the DB.rateLimitOverridesrefresh (refreshConnectionRateLimits) is preserved unconditionally since it is useful on its own and does not affect the enable/disable toggle.rateLimitProtectionitself is not (and was not) part ofupdateProviderConnectionSchema, so this route can only read the persisted value — never set it — closing the drift for good.Closes #11278
Test plan
TDD per Hard Rule #18 —
tests/unit/provider-patch-ratelimit-protection-11278.test.ts:RED (confirmed by code inspection of the base branch's unconditional
enableRateLimitProtection(id)call — see diff) → GREEN after the fix: a connection withrate_limit_protection=falsein the DB stays withisRateLimitEnabled() === falseafter aPUTthat includesrateLimitOverrides: null, and the DB row itself still shows protection off.Control case: a connection with
rate_limit_protection=truekeepsisRateLimitEnabled() === trueafter the same kind ofPUT.node --import tsx/esm --test tests/unit/provider-patch-ratelimit-protection-11278.test.ts— 2/2 passSibling suites (route + rate-limit-manager):
providers-patch-400.test.ts,codex-connection-edit-6562.test.ts,provider-rate-limit-overrides-schema.test.ts,providers-route-patch-method.test.ts,rate-limit-manager.test.ts,ratelimitmanager-headers-split.test.ts— 56/56 passnpm run typecheck:core— cleaneslinton changed files with the project suppressions — clean (the one pre-existingno-restricted-importswarning onroute.tsline 7 is already allowlisted inconfig/quality/eslint-suppressions.jsonand untouched by this change)