validateSettings() doesn't validate rateLimits[].period — zero period silently degrades to a 1ms backoff hint
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 82/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- typescript
- 领域
- backend
调研方向
从 src/utils/settings-config.ts 开始,那里的 validateSettings() 已经检查 pow.periodMs > 0,然后阅读 src/@types/settings.ts 中的 RateLimit 类型。在该检查旁边,对每个 limits.*.rateLimits 数组(以及 limits.admin.loginRateLimits)添加一个循环,当 period 不大于 0 时,推入一个 { path, message } 问题。完成的标准是:周期为零或负数时,启动验证失败,且问题中指明了路径;现有的设置测试仍然全部通过。
由索引模型根据 Issue 内容生成。
描述
Problem
validateSettings() (src/utils/settings-config.ts) enforces pow.periodMs > 0, but nothing validates period on any rateLimits[] entry. The RateLimit type (src/@types/settings.ts) declares period: number as required, so period: 0 passes type checks and startup validation without a word.
Since #807, a rejected request carries a retry-after hint computed as Math.max(1, Math.ceil(period)) ms. With period: 0 that emits a protocol-valid 1ms backoff — the misconfiguration is silently masked instead of failing loudly at startup. (It also degenerates the EWMA decay itself: λ = ln(2)/0, so prior activity decays to zero instantly and every event is judged in isolation.)
Affected arrays
All of these accept a RateLimit[] whose period is never validated:
limits.event.rateLimitslimits.message.rateLimitslimits.connection.rateLimitslimits.invoice.rateLimitslimits.admissionCheck.rateLimitslimits.invite.rateLimitslimits.admin.rateLimitsandlimits.admin.loginRateLimits
Suggested fix
In validateSettings(), next to the existing pow.periodMs check, iterate each rate-limit array and push a { path: 'limits.….rateLimits[i].period', message: 'period must be greater than 0' } issue when !(period > 0) — same style as the existing checks.
From Muse
- 主要语言
- TypeScript
- 星标
- 829
- 派生
- 234
- 平均合并
- 4 天 5 小时
- 30 天内合并 PR
- 22
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
cameri/nostream 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backend可能已有人在做 @Priyanshubhartistm 于 2 天前认领。 未关闭enhancement
cameri/nostream#801 · 已指派 1 人 ·
维护者通常 1 天内回复
-
feat(admin): bounded NIP-66 probe history and Network Health timeline可能已有人在做 @Ferryx349 于 2 天前认领。 未关闭Admin Console enhancement
cameri/nostream#800 · 已指派 1 人 ·
维护者通常 1 天内回复
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)可能重新可做 @Ferryx349 于 35 天前认领,目前没有进行中的 PR。 未关闭enhancement
cameri/nostream#757 · 已指派 1 人 ·
维护者通常 1 天内回复
-
feat(nip85): Web-of-Trust spam mitigation engine可能重新可做 @Ferryx349 于 66 天前认领,目前没有进行中的 PR。 未关闭enhancement
cameri/nostream#720 · 已指派 1 人 ·
维护者通常 1 天内回复
相似的 Issue
-
bug p3 triaged
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 1 天内回复
-
bug javascript P2-medium python release:v3.1
难度 2/5 1-3 小时 新手友好度 68/100
adrirubio/claude-deck#546 ·
维护者通常 1 天内回复
-
area: desktop area: website priority: P2 type: feature
难度 2/5 1-3 小时 新手友好度 62/100
appandflow/stim#3411 · 1 条评论 ·
维护者通常 1 天内回复
-
needs triage
难度 2/5 1-3 小时 新手友好度 65/100
rjsf-team/react-jsonschema-form#5485 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 6 天内回复