Skip to content

test(server): cover API rate limiter middleware - #334

Open
tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:test/rate-limit-middleware
Open

tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:test/rate-limit-middleware

Conversation

@tahodev

@tahodev tahodev commented Sep 25, 2026

Copy link
Copy Markdown

What

Adds behavioral tests for the previously untested apiRateLimiter middleware (packages/server/src/middleware/rate-limit.ts). No production code changes.

Why

This middleware enforces the general API budget (100 requests/minute) and owns two security-relevant behaviors that had no regression coverage:

  • the skip list for health checks, webhook endpoints, and Better Auth routes, including its path normalization that exists to prevent bypasses;
  • keying by authenticated user id with a fall back to client IP, so one caller cannot exhaust another caller's budget.

Coverage added

  • 100 requests succeed and the 101st returns 429 with the { error: { code: "rate_limited" } } body for anonymous callers.
  • Separate buckets for different client IPs.
  • Authenticated requests are keyed by user id, not IP (a second user on the same IP keeps a fresh budget; the first user stays limited).
  • /api/health, /api/webhook, /api/webhooks/*, /api/auth, and /api/auth/* are never rate limited, even past the limit.
  • enabled: false disables limiting entirely.

Tests build a minimal Hono app with the existing createMemoryApiRateLimitStorage() helper, so they run fully in memory.

Validation

  • vitest run src/middleware/rate-limit.test.ts — 9/9 pass.
  • oxfmt --check passes on the new file.
  • Note: local oxlint aborts with a Rust allocator panic in this environment, so lint was not run locally.

Add behavioral tests for the previously untested apiRateLimiter
middleware: the 100-requests-per-minute limit and 429 contract for
anonymous callers, per-IP and per-user bucket isolation, the skip list
for health checks, webhooks, and Better Auth routes, and the disabled
mode.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant