Skip to content

release/v1.6.66 - #282

Merged
roncodes merged 5 commits into
mainfrom
release/v1.6.66
Sep 29, 2026
Merged

roncodes merged 5 commits into
mainfrom
release/v1.6.66

Conversation

@roncodes

Copy link
Copy Markdown
Member

Release v1.6.66: per-consumer API rate limiting, admin rate-limit controls, and API consumer metrics. The notes are in RELEASE.md.

Includes:

Merge those into this branch first. Merging this branch into main tags v1.6.66.

…y IP

ThrottleRequests runs before API authentication, so Laravel's default
signature always fell back to route domain + client IP. Behind a load
balancer that IP is the balancer's, and no route has a domain, so every
tenant, API key and console visitor shared one bucket: one busy
integration returned 429 to the whole platform.

Key the limiter on the hashed credential (API key, Sanctum token, basic
auth), falling back to the user and then the IP only when none is sent,
and scope it by first path segment so /v1 and /int stay separate.

Also keep Retry-After and X-RateLimit-* on the 429 response so throttled
clients know when to retry.
…umer metrics

- ApiRateLimits: effective limits from env defaults plus a system.rate-limits
  setting an admin can change at runtime; per-organization overrides (custom
  limit or unlimited); credential -> organization lookup cached per key.
- ApiConsumerMetrics: per-consumer request and 429 counts in Redis
  (minute buckets for 2h, hour buckets for 8 days), recorded by the
  throttle middleware so throttled requests are visible too.
- RateLimitController + int/v1/rate-limits routes (admin only): get/save/reset
  settings, top consumers by window, clear a consumer's limiter window.
- ThrottleRequests applies overrides and records every request.
@roncodes
roncodes force-pushed the release/v1.6.66 branch 2 times, most recently from f4fc81a to 2f008a8 Compare September 29, 2026 08:28
@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (b82d921) to head (057cfd0).

Additional details and impacted files
@@             Coverage Diff              @@
##                main      #282    +/-   ##
============================================
  Coverage     100.00%   100.00%            
- Complexity      7676      7772    +96     
============================================
  Files            433       436     +3     
  Lines          25009     25337   +328     
============================================
+ Hits           25009     25337   +328     
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

fix(throttle): key the API rate limiter on the consumer, not the proxy IP
feat(throttle): admin-managed rate limits, org overrides and API consumer metrics
@roncodes
roncodes merged commit 74cc07c into main Sep 29, 2026
7 checks passed
@roncodes
roncodes deleted the release/v1.6.66 branch September 29, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant