diff --git a/d6ee-defensive-relay-features.md b/d6ee-defensive-relay-features.md index fb9d923..75e76b7 100644 --- a/d6ee-defensive-relay-features.md +++ b/d6ee-defensive-relay-features.md @@ -37,6 +37,7 @@ 2. Add max_connections configuration (default: 500) 3. Update all 4 config locations (CRITICAL - see AGENTS.md) 4. Fix documentation error (filter limit 5000→500) +5. Document Phase 2 deferral decision in defensive-measures.md **Files to modify:** - `src/nostr/builder.rs` - Add explicit RateLimit and max_connections @@ -44,17 +45,19 @@ - `.env.example` - Add NGIT_MAX_CONNECTIONS - `nix/module.nix` - Add maxConnections option - `docs/reference/configuration.md` - Document new option -- `docs/explanation/defensive-measures.md` - Fix filter limit error +- `docs/explanation/defensive-measures.md` - Fix filter limit error + document Phase 2 deferral **Effort:** 2-3 hours **Acceptance Criteria:** -- ✅ RateLimit explicitly configured in builder.rs with comments -- ✅ max_connections configurable via NGIT_MAX_CONNECTIONS (default: 500) -- ✅ All 4 config locations synced -- ✅ Documentation error fixed -- ✅ Integration test: Connection rejected after reaching total limit -- ✅ All tests passing +- [ ] RateLimit explicitly configured in builder.rs with comments +- [ ] max_connections configurable via NGIT_MAX_CONNECTIONS (default: 500) +- [ ] All 4 config locations synced +- [ ] Documentation error fixed (filter limit 5000→500) +- [ ] Documentation updated with Phase 2 deferral decision +- [ ] Integration test: Connection rejected after reaching total limit +- [ ] All tests passing +- [ ] Changes committed ### Phase 2 & 3: Per-IP Enforcement (DEFERRED - Future Work) @@ -79,9 +82,9 @@ **Implementation details preserved below for future reference.** -### Git Endpoint IP-Based Throttling (SEPARATE ANALYSIS NEEDED) +### Git Endpoint IP-Based Throttling (MOVED TO SEPARATE ISSUE) -**Status:** Needs separate analysis with architect subagent +**Status:** ✅ Spun out to issue ff38 **Rationale:** - Git data fetching has different threat model than Nostr relay @@ -89,7 +92,7 @@ - Different attack vectors (bandwidth, CPU for pack generation) - Should NOT interact with relay code -**Next:** Analyze requirements before proceeding with Phase 1 +**See:** Issue ff38 (git-endpoint-ip-throttling) for full analysis and implementation plan ---