Skip to content

feat: apply rate limit for jwt token verification - #1111

Open
merll wants to merge 1 commit into
APL-2195from
feat-ws-rate-limiting
Open

merll wants to merge 1 commit into
APL-2195from
feat-ws-rate-limiting

Conversation

@merll

@merll merll commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR adds rate limiting to the JWT verification for websockets.

@merll
merll added this pull request to stack #1112 October 7, 2026 13:55
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation is correctly ordered, proxy-aware, concurrency-safe, and comprehensively tested.

Review effort: Balanced
Findings: None

What changed in this PR

Adds per-IP rate limiting before websocket JWT verification, sharing the existing REST authentication budget.

Changes:

  • Adds trusted-proxy-aware Socket.IO rate limiting.
  • Releases reservations after successful authentication.
  • Adds coverage for limits, concurrency, proxy handling, and REST sharing.
File Description
src/​middleware/​session.ts Applies rate limiting before websocket JWT verification.
src/​middleware/​session.test.ts Tests websocket authentication integration.
src/​middleware/​rate-limit.ts Implements shared socket/REST authentication limiting.
src/​middleware/​rate-limit.test.ts Tests rate-limit behavior and edge cases.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants