Skip to content

fix: make the connector rate limit atomic (#228) - #240

Merged
pluginslab merged 1 commit into
mainfrom
fix/228-review-29sep
Sep 30, 2026
Merged

pluginslab merged 1 commit into
mainfrom
fix/228-review-29sep

Conversation

@pluginslab

Copy link
Copy Markdown
Owner

Answers the only item in WP.org's 29 Sep review (R agentic-admin/28May26/T5). Remote loading, escaping and Tested up to are no longer listed after #238 and #239.

Flag (class-connectors.php:505, their AI): the rate limit read a transient and then wrote count + 1, so concurrent requests could read the same value and get past the per-user limit.

Fix:

  • The counter is now an options row, incremented with one INSERT … ON DUPLICATE KEY UPDATE option_value = option_value + 1. The database applies that atomically.
  • There's one row per user per clock minute. This user's older rows are deleted on each request, and all rows are deleted on uninstall.

Tested:

  • 40 concurrent requests as the same admin against the limit of 30 allowed exactly 30, twice, with no database errors.
  • PHPCS clean. Plugin Check reports nothing for these files.

🤖 Generated with Claude Code

WP.org review R agentic-admin/28May26/T5 (29 Sep, AI-flagged): the
transient-based counter was read-then-written, so concurrent requests
could read the same count and bypass the per-user limit.

The counter is now an options row incremented with a single
INSERT ... ON DUPLICATE KEY UPDATE, which the database applies
atomically, with one row per user per clock minute. Older rows are
deleted as it goes and on uninstall.

Tested: 40 concurrent requests as one user against a limit of 30
allowed exactly 30 (twice), with no database errors.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@pluginslab
pluginslab merged commit 28aea9f into main Sep 30, 2026
4 checks passed
@pluginslab
pluginslab deleted the fix/228-review-29sep branch September 30, 2026 09:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant