validateSettings() doesn't validate rateLimits[].period — zero period silently degrades to a 1ms backoff hint
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 82/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- typescript
- Área
- backend
Línea de trabajo
Empieza en src/utils/settings-config.ts, donde validateSettings() ya comprueba pow.periodMs > 0, y lee el tipo RateLimit en src/@types/settings.ts. Añade un bucle junto a esa comprobación sobre cada array limits.*.rateLimits (más limits.admin.loginRateLimits), agregando una incidencia { path, message } cuando period no sea mayor que 0. Está terminado cuando un período cero o negativo hace fallar la validación al iniciar, con la ruta indicada en la incidencia, y las pruebas existentes de la configuración siguen pasando.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem
validateSettings() (src/utils/settings-config.ts) enforces pow.periodMs > 0, but nothing validates period on any rateLimits[] entry. The RateLimit type (src/@types/settings.ts) declares period: number as required, so period: 0 passes type checks and startup validation without a word.
Since #807, a rejected request carries a retry-after hint computed as Math.max(1, Math.ceil(period)) ms. With period: 0 that emits a protocol-valid 1ms backoff — the misconfiguration is silently masked instead of failing loudly at startup. (It also degenerates the EWMA decay itself: λ = ln(2)/0, so prior activity decays to zero instantly and every event is judged in isolation.)
Affected arrays
All of these accept a RateLimit[] whose period is never validated:
limits.event.rateLimitslimits.message.rateLimitslimits.connection.rateLimitslimits.invoice.rateLimitslimits.admissionCheck.rateLimitslimits.invite.rateLimitslimits.admin.rateLimitsandlimits.admin.loginRateLimits
Suggested fix
In validateSettings(), next to the existing pow.periodMs check, iterate each rate-limit array and push a { path: 'limits.….rateLimits[i].period', message: 'period must be greater than 0' } issue when !(period > 0) — same style as the existing checks.
From Muse
- Lenguaje dominante
- TypeScript
- Estrellas
- 829
- Forks
- 234
- Merge medio
- 4 d 5 h
- PR fusionados (30 d)
- 22
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cameri/nostream
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backendPosiblemente ocupada @Priyanshubhartistm la tomó hace 2 días. Abiertoenhancement
cameri/nostream#801 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
feat(admin): bounded NIP-66 probe history and Network Health timelinePosiblemente ocupada @Ferryx349 la tomó hace 2 días. AbiertoAdmin Console enhancement
cameri/nostream#800 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)Quizá libre de nuevo @Ferryx349 la tomó hace 35 días y no hay ningún pull request abierto. Abiertoenhancement
cameri/nostream#757 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
feat(nip85): Web-of-Trust spam mitigation engineQuizá libre de nuevo @Ferryx349 la tomó hace 66 días y no hay ningún pull request abierto. Abiertoenhancement
cameri/nostream#720 · 1 asignado ·
Los mantenedores suelen responder en 1 día
Todos los issues de cameri/nostream
Issues similares
-
bug p3 triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
bug javascript P2-medium python release:v3.1
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
adrirubio/claude-deck#546 ·
Los mantenedores suelen responder en 1 día
-
area: desktop area: website priority: P2 type: feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
appandflow/stim#3411 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
rjsf-team/react-jsonschema-form#5485 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 6 días