Files
sim/apps/docs/openapi.json
T
Waleed 79b1ed1fa1 fix(api): report the real rate-limit ceiling on every v1 endpoint (#6011)
X-RateLimit-Limit was the bucket's refill rate while X-RateLimit-Remaining
was tokens left in the bucket, and createBucketConfig sets
maxTokens = refillRate * burstMultiplier. The two headers described different
quantities, so remaining routinely exceeded limit — observed live on a team
plan as limit 200 alongside remaining 399 — and any client computing
used = limit - remaining got a negative number. Report the bucket capacity,
which is what remaining counts down from.

This lives in the shared checkRateLimit, so it applies to every v1 endpoint:
workflows, logs, tables, files, knowledge, audit-logs and copilot.

Also stops publishing rate-limit headers on an authentication failure. That
path never reaches the bucket, so the previous placeholder advertised a quota
that does not exist and told unauthenticated callers they had been throttled.

Separately, the shared id schemas reported Zod's default "expected string,
received undefined" when a required field was omitted, because .min(1) only
fires for a present-but-empty string. Adding the message to the z.string()
constructor makes an omitted workspaceId/organizationId/workflowId/fileId
name the field it is complaining about — the first thing an API consumer sees
on a malformed request.

Documents all three headers in the OpenAPI spec as reusable components,
including the burst-capacity semantics and the fact that they are absent on
authentication failures. They were previously undocumented.

Adds the first tests for the v1 middleware.
2026-07-28 11:42:42 -07:00

277 KiB