mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-06 07:28:23 +00:00
Update issue d6ee: Clarify Phase 1 scope, reference ff38 for git throttling
This commit is contained in:
@@ -37,6 +37,7 @@
|
||||
2. Add max_connections configuration (default: 500)
|
||||
3. Update all 4 config locations (CRITICAL - see AGENTS.md)
|
||||
4. Fix documentation error (filter limit 5000→500)
|
||||
5. Document Phase 2 deferral decision in defensive-measures.md
|
||||
|
||||
**Files to modify:**
|
||||
- `src/nostr/builder.rs` - Add explicit RateLimit and max_connections
|
||||
@@ -44,17 +45,19 @@
|
||||
- `.env.example` - Add NGIT_MAX_CONNECTIONS
|
||||
- `nix/module.nix` - Add maxConnections option
|
||||
- `docs/reference/configuration.md` - Document new option
|
||||
- `docs/explanation/defensive-measures.md` - Fix filter limit error
|
||||
- `docs/explanation/defensive-measures.md` - Fix filter limit error + document Phase 2 deferral
|
||||
|
||||
**Effort:** 2-3 hours
|
||||
|
||||
**Acceptance Criteria:**
|
||||
- ✅ RateLimit explicitly configured in builder.rs with comments
|
||||
- ✅ max_connections configurable via NGIT_MAX_CONNECTIONS (default: 500)
|
||||
- ✅ All 4 config locations synced
|
||||
- ✅ Documentation error fixed
|
||||
- ✅ Integration test: Connection rejected after reaching total limit
|
||||
- ✅ All tests passing
|
||||
- [ ] RateLimit explicitly configured in builder.rs with comments
|
||||
- [ ] max_connections configurable via NGIT_MAX_CONNECTIONS (default: 500)
|
||||
- [ ] All 4 config locations synced
|
||||
- [ ] Documentation error fixed (filter limit 5000→500)
|
||||
- [ ] Documentation updated with Phase 2 deferral decision
|
||||
- [ ] Integration test: Connection rejected after reaching total limit
|
||||
- [ ] All tests passing
|
||||
- [ ] Changes committed
|
||||
|
||||
### Phase 2 & 3: Per-IP Enforcement (DEFERRED - Future Work)
|
||||
|
||||
@@ -79,9 +82,9 @@
|
||||
|
||||
**Implementation details preserved below for future reference.**
|
||||
|
||||
### Git Endpoint IP-Based Throttling (SEPARATE ANALYSIS NEEDED)
|
||||
### Git Endpoint IP-Based Throttling (MOVED TO SEPARATE ISSUE)
|
||||
|
||||
**Status:** Needs separate analysis with architect subagent
|
||||
**Status:** ✅ Spun out to issue ff38
|
||||
|
||||
**Rationale:**
|
||||
- Git data fetching has different threat model than Nostr relay
|
||||
@@ -89,7 +92,7 @@
|
||||
- Different attack vectors (bandwidth, CPU for pack generation)
|
||||
- Should NOT interact with relay code
|
||||
|
||||
**Next:** Analyze requirements before proceeding with Phase 1
|
||||
**See:** Issue ff38 (git-endpoint-ip-throttling) for full analysis and implementation plan
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user