Vikhyath Mondreti 9a66fbb774 fix(auth): bound the three unbounded session-policy caches (#6919)
* fix(auth): bound the three unbounded session-policy caches

security-policy.ts and session-policy.ts are read from Better Auth's session
create and update hooks, so they run on every session validation. All three
caches were plain Maps with a hand-rolled 'Date.now() - fetchedAt < TTL' read
and no ceiling: entries were released only by an explicit invalidate, so they
grew for the life of the process. membershipCache is the sharpest of the three
because it is keyed by user, not organization — one entry per user who ever
authenticated on that instance.

Move all three to LRUCache, already a direct dependency and the pattern
copilot/entitlements.ts and providers/client-cache.ts use. The library owns the
TTL and the ceiling; every existing invalidate* keeps working unchanged.

Two things to preserve, both now pinned by tests:
- membership results keep their asymmetric TTL (a non-member result expires far
  sooner, so a user who joins through a path this codebase never sees cannot
  dodge the new org's policy). Expressed as membershipCacheTtlMs rather than an
  inline ternary, since it is a security property and not a tuning knob.
- reads test '!== undefined', because a version is a number and a membership is
  nullable — a truthiness check would treat both as a miss.

security-policy.ts had no test file; adds one covering caching, invalidation,
failure fallbacks and the TTL asymmetry.

* fix(auth): raise the cache ceilings to a memory backstop

getSessionCookieCacheVersion feeds Better Auth's session.cookieCache.version,
so these are read on every session read, not just create/refresh. At max: 1000
a busy instance could exceed the live key set inside the 60s TTL and start
evicting early — never a wrong answer (a miss is one indexed lookup, exactly
the pre-cache behaviour) but a hit-rate cliff on a hot path.

Entries are a few dozen bytes, so headroom is nearly free: orgs 1k -> 20k,
users 10k -> 100k. That is single-digit MB at worst and puts the ceiling far
above any plausible per-instance working set, leaving it as the memory backstop
it was meant to be.

* docs(rules): write down the caching decision tree

The lifecycle-map-vs-TTL-cache distinction, the ceiling-as-backstop sizing, and
the fetchMethod-unless-you-need-a-hang-deadline call each took real digging to
settle. Recording them so the next cache does not re-derive the same answers —
or re-introduce the unbounded tenant-keyed Map this branch just removed.

Notes the two non-obvious traps behind that: ttl alone does not bound memory
without a ceiling, and React cache() is a no-op in Trigger workers, so a gate
that looks free on a settings page is uncached and per-block on the executor.
2026-08-20 18:29:48 -07:00

Sim.ai Documentation Slack X

Ask DeepWiki Set Up with Cursor

Sim — Integrate, Context, Build, and Monitor AI agents

A workspace to build, deploy and manage AI agents and workflows.

Quickstart

Cloud-hosted: sim.ai

Open sim.ai

Self-hosted

npx sim-setup

Open http://localhost:3000

The Sim platform — chat on the left, the visual workflow builder on the right

Capabilities

  • Connect 1,000+ integrations and every major LLM
  • Add Slack, Notion, HubSpot, Salesforce, databases, and more
  • Build agents visually, conversationally, or with code
  • Ingest files, knowledge bases, and structured table data
  • Monitor runs, logs, schedules, and workflow activity

One workspace, every surface

Chat and workflows are just the start — tables, files, and knowledge all live in the same workspace.

Tables in Sim — structured data your agents can query

Tables — a database, built in

Files in Sim — documents for your team and every agent

Files — one store for your team and every agent

Knowledge bases in Sim — synced docs your agents can search

Knowledge — your agents' memory

Self-hosting

Requirements: Node.js 20+ and Docker.

npx sim-setup is an interactive wizard that creates a small sim/ deployment directory, provisions the database, generates secrets, writes .env, connects a Chat API key, and starts the published Sim images with Docker Compose. It does not clone the repository.

When it finishes, open http://localhost:3000.

Inside a cloned Sim repository, run bun run sim-setup to unlock the source-only local development and Kubernetes modes.

Reconfigure an optional capability without rerunning the full wizard:

npx sim-setup config
npx sim-setup add email
npx sim-setup add storage
npx sim-setup add sandbox
npx sim-setup add jobs
npx sim-setup add cache
npx sim-setup add knowledge
npx sim-setup add llm
npx sim-setup add integration slack

npx sim-setup config detects the effective local-dev, Docker Compose, or current-context Helm configuration and reports configured, missing, or invalid capabilities and OAuth integrations without printing credential values. This is separate from npx sim-setup status, which reports whether installed services are running and healthy.

Manage your install from its directory:

npx sim-setup start | stop | restart   # bring your install up / down / cycle
npx sim-setup update                   # pull and apply Compose images
npx sim-setup status                   # what's installed and healthy
npx sim-setup logs                     # follow logs
npx sim-setup doctor                   # diagnose configuration problems
npx sim-setup down                     # remove containers (data kept)
npx sim-setup reset                    # archive .env and wipe managed data

The setup package detects how you're running and acts accordingly. Use --dir <path> to create or manage a deployment somewhere other than ./sim.

Sim also supports local models via Ollama and vLLM. See the self-hosting docs for details.

Chat API Keys

Chat is a Sim-managed service. npx sim-setup connects a Chat API key for you — sign in when it opens your browser and the key is stored automatically. To view, create, or revoke keys later, go to sim.ai/selfhost/settings/chat-keys.

Environment Variables

See the environment variables reference for the full list, or apps/sim/.env.example for defaults.

Tech Stack

Next.js · Bun · PostgreSQL · Drizzle · Better Auth · Tailwind — and the rest of the stack

Contributing

We welcome contributions! Please see our Contributing Guide for details.

License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.

Built by the Sim team in San Francisco

Languages
TypeScript 77%
MDX 20.8%
JavaScript 1.9%
CSS 0.1%