Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 1 | /** |
| 2 | * The front door's rate limits (workers/app.ts), per request before it is | |
| 3 | * answered. The bindings and their limits are in `RATE_LIMITS` | |
| The docs folder is gone, and what it held lives where people read it: how a self-hosted g1t runs and how to deploy g1t to Cloudflare are pages on docs.g1t.sh under Run g1t yourself, and speed, rate limits and operating g1t.sh are sections of CONTRIBUTING.md; code that cited a file in docs/ now points to the page or section that covers it, or says what it means itself, and applied migrations and the runner images are left as they were. | 4 | * (packages/contracts/src/rate-limits.ts); CONTRIBUTING.md, "Rate limits", |
| 5 | * says how they are kept. | |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 6 | * |
| 7 | * - Git over HTTPS: without credentials, by address; with them, by a hash | |
| 8 | * of the credential, much higher. A clone is about three requests. | |
| 9 | * - Pages: every request that reaches the Worker counts against a ceiling | |
| 10 | * per address. Signed out, by address, with a tighter limit on what is | |
| 11 | * costly to answer (archives, run pages, logs, search). Signed in, by a | |
| 12 | * hash of the session cookie, higher: the session is not checked here, | |
| 13 | * which would cost a call to identity, and the ceiling per address keeps | |
| Merge main into Artifacts Phase 2 | 14 | * made-up cookies from getting round the signed-out limit. With an |
| 15 | * access token (`Authorization: Bearer`, app/lib/website-token.ts), by a | |
| 16 | * hash of the token, at the API's limit for a token; the address ceiling | |
| 17 | * applies as for cookies. | |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 18 | * |
| 19 | * Static assets never reach the Worker (the assets binding answers them), | |
| 20 | * and the few files it serves itself are left out here too. Every limit | |
| 21 | * fails open. | |
| 22 | */ | |
| 23 | import { | |
| 24 | type RateLimitBinding, | |
| 25 | checkLimit, | |
| 26 | clientAddress, | |
| 27 | secretKey, | |
| 28 | tooManyRequests, | |
| 29 | } from "@g1t/contracts/rate-limits"; | |
| 30 | ||
| 31 | export type FrontDoorLimits = { | |
| 32 | WEB_ANONYMOUS_LIMIT?: RateLimitBinding; | |
| 33 | WEB_HEAVY_LIMIT?: RateLimitBinding; | |
| 34 | WEB_SESSION_LIMIT?: RateLimitBinding; | |
| 35 | WEB_ADDRESS_LIMIT?: RateLimitBinding; | |
| Merge main into Artifacts Phase 2 | 36 | WEB_TOKEN_LIMIT?: RateLimitBinding; |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 37 | GIT_ANONYMOUS_LIMIT?: RateLimitBinding; |
| 38 | GIT_SIGNED_LIMIT?: RateLimitBinding; | |
| 39 | }; | |
| 40 | ||
| 41 | /** Files the Worker serves that are never limited: build output, fonts, and top-level files such as robots.txt. */ | |
| 42 | const UNLIMITED = /^\/(?:assets\/|fonts\/|favicon|[^/]+\.(?:ico|png|svg|txt|xml|webmanifest)$)/; | |
| 43 | ||
| 44 | /** What is costly to answer for a signed-out visitor: a repository's archives, a run's page, logs and artifacts, and search. */ | |
| 45 | const HEAVY = | |
| 46 | /^\/(?:search(?:\.data)?$|[^/]+\/[^/]+\/(?:archive\/|actions\/runs\/[^/]+(?:\.data|\/logs\.zip|\/artifacts\/[^/]+)?$|actions\/jobs\/[^/]+\/log))/; | |
| 47 | ||
| 48 | export function unlimited(pathname: string): boolean { | |
| 49 | return UNLIMITED.test(pathname); | |
| 50 | } | |
| 51 | ||
| 52 | export function heavy(pathname: string): boolean { | |
| 53 | return HEAVY.test(pathname); | |
| 54 | } | |
| 55 | ||
| 56 | /** The session cookie's value, or null when signed out. */ | |
| 57 | export function sessionCookie(cookie: string | null): string | null { | |
| 58 | const match = /(?:^|;\s*)g1t_session=([^;]+)/.exec(cookie ?? ""); | |
| 59 | return match?.[1] ?? null; | |
| 60 | } | |
| 61 | ||
| 62 | const GIT_MESSAGE_ANONYMOUS = | |
| 63 | "Too many git requests from your network. Wait a minute and try again, or use credentials for a higher limit: https://docs.g1t.sh/reference/rate-limits/\n"; | |
| 64 | const GIT_MESSAGE_SIGNED = "Too many git requests with these credentials. Wait a minute and try again: https://docs.g1t.sh/reference/rate-limits/\n"; | |
| 65 | const PAGE_MESSAGE = "Too many requests from your network. Wait a minute and try again.\n"; | |
| Merge main into Artifacts Phase 2 | 66 | const TOKEN_PAGE_MESSAGE = "Too many requests with this access token. Wait a minute and try again: https://docs.g1t.sh/reference/rate-limits/\n"; |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 67 | |
| 68 | /** | |
| 69 | * The 429 for a git request past its limit, or null to go on. Git shows a | |
| 70 | * plain-text answer's body to the person running it. | |
| 71 | */ | |
| 72 | export async function gitLimited(env: FrontDoorLimits, request: Request): Promise<Response | null> { | |
| 73 | const credentials = request.headers.get("authorization"); | |
| 74 | if (credentials) { | |
| 75 | const verdict = await checkLimit(env.GIT_SIGNED_LIMIT, await secretKey("git", credentials)); | |
| 76 | return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_SIGNED) : null; | |
| 77 | } | |
| 78 | const verdict = await checkLimit(env.GIT_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`); | |
| 79 | return verdict === "limited" ? tooManyRequests(GIT_MESSAGE_ANONYMOUS) : null; | |
| 80 | } | |
| 81 | ||
| Merge main into Artifacts Phase 2 | 82 | /** |
| 83 | * The token in a page request's `Authorization: Bearer` header, or null | |
| 84 | * (app/lib/website-token.ts). Not checked here either. | |
| 85 | */ | |
| 86 | export function websiteToken(authorization: string | null): string | null { | |
| 87 | return /^\s*bearer\s+(\S+)\s*$/i.exec(authorization ?? "")?.[1] ?? null; | |
| 88 | } | |
| 89 | ||
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 90 | /** The 429 for a page or data request past its limit, or null to go on. */ |
| 91 | export async function pageLimited(env: FrontDoorLimits, request: Request, pathname: string): Promise<Response | null> { | |
| 92 | if (unlimited(pathname)) return null; | |
| 93 | const address = `ip:${clientAddress(request)}`; | |
| Merge main into Artifacts Phase 2 | 94 | const token = websiteToken(request.headers.get("authorization")); |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 95 | const session = sessionCookie(request.headers.get("cookie")); |
| 96 | const checks: Promise<string>[] = [checkLimit(env.WEB_ADDRESS_LIMIT, address)]; | |
| Merge main into Artifacts Phase 2 | 97 | if (token) { |
| 98 | // A token on the website: per token, as the API counts it. | |
| 99 | checks.push(secretKey("token", token).then((key) => checkLimit(env.WEB_TOKEN_LIMIT, key))); | |
| 100 | } else if (session) { | |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 101 | checks.push(secretKey("session", session).then((key) => checkLimit(env.WEB_SESSION_LIMIT, key))); |
| 102 | } else { | |
| 103 | checks.push(checkLimit(env.WEB_ANONYMOUS_LIMIT, address)); | |
| 104 | if (heavy(pathname)) checks.push(checkLimit(env.WEB_HEAVY_LIMIT, address)); | |
| 105 | } | |
| 106 | const verdicts = await Promise.all(checks); | |
| 107 | if (!verdicts.includes("limited")) return null; | |
| Merge main into Artifacts Phase 2 | 108 | if (token && verdicts[1] === "limited") return tooManyRequests(TOKEN_PAGE_MESSAGE); |
| 109 | return tooManyRequests(token || session ? PAGE_MESSAGE : `${PAGE_MESSAGE.trimEnd()} Signed-in accounts have a higher limit.\n`); | |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 110 | } |
| Merge g1tusercontent.com: registry answers run nothing in a browser, the site's pages run only their own scripts, repository files and avatars on their own origin, raw files rate limited per address | 111 | |
| 112 | /** | |
| 113 | * The 429 for a repository file on the usercontent origin past its limit, | |
| 114 | * or null to go on. Nothing there is signed in (it never sees the session | |
| 115 | * cookie), so a file counts as a signed-out page from its address. Avatars | |
| Merge the workspace shell: navigation and phone shell, g1t as orchestrator, agents in roles with audience-checked reads, reactions and custom emoji, live notifications and browser push, the homepage tour (agents 0002, chat 0002) | 116 | * and custom emoji are answered from cache and are not limited. |
| Merge g1tusercontent.com: registry answers run nothing in a browser, the site's pages run only their own scripts, repository files and avatars on their own origin, raw files rate limited per address | 117 | */ |
| 118 | export async function usercontentLimited(env: FrontDoorLimits, request: Request, path: string): Promise<Response | null> { | |
| Merge the workspace shell: navigation and phone shell, g1t as orchestrator, agents in roles with audience-checked reads, reactions and custom emoji, live notifications and browser push, the homepage tour (agents 0002, chat 0002) | 119 | if (path.startsWith("/avatars/") || path.startsWith("/emoji/")) return null; |
| Merge g1tusercontent.com: registry answers run nothing in a browser, the site's pages run only their own scripts, repository files and avatars on their own origin, raw files rate limited per address | 120 | const verdict = await checkLimit(env.WEB_ANONYMOUS_LIMIT, `ip:${clientAddress(request)}`); |
| 121 | return verdict === "limited" ? tooManyRequests(PAGE_MESSAGE) : null; | |
| 122 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.