Round 2 of review on the same branch:
- The fail-closed capacity guard was itself a DoS lever. MAX_RATE_KEYS was
global, and the limiter runs before auth, so a flood of cheap /v1/repos
keys could exhaust the table and 429 never-seen /v1/link clients until
live windows expired. Budgets are now per route.
- Rule values accepted booleans: bool subclasses int, so isinstance let
[5, true] through as a 1-SECOND window (5/hour -> ~5/sec) and false in the
limit slot disabled the endpoint. Now `type(x) is int`.
- trusted_proxies was unvalidated: a bare string would be iterated character
by character, malformed entries only surfaced as a per-request log line,
and 0.0.0.0/0 or ::/0 restored "trust XFF from any peer" — the exact hole
the setting closes. Now parsed and validated once at startup, wildcards
refused, and _ip_in_any takes pre-parsed networks so nothing can degrade
to a silent per-request skip.
Tests 99 -> 108: cross-route flood isolation, per-route reclamation windows,
every bool-in-rule position, bare-string and wildcard proxies, and a v4/v6
mismatch case.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01LTARYHX7GPepi3CH3tp5pg