writeonce/docs/examples/porch/middleware
shoney.arickathil 491c2f42b4 feat(porch-store): limiter delegates all counting to the key pool
- delete all RateLimitCounter access from limiter.wo: query, increment,
  delete-then-insert, and the swallowing catch (e) nil -- the pool is now
  the only writer, so its serialization guarantee actually holds
- Limiter gains pool/limit/trust_proxy fields; before() calls pool_count
  and acts on the Verdict; make_limiter takes a pool
- key selection: req.principal first, else trust_proxy ? client_ip(req)
  : net.peer(req.conn); delete the dead req.ctx["verified_proxy"] branch
- 429 on a spent window (Retry-After, X-RateLimit-*); 503 + Retry-After
  on a caught actor trap (saturated pool), request never let through
- add Limiter.after(), registered alongside before() as both Mw and Aw
  (Cors's own shape) so the allowed path's X-RateLimit-* headers reach
  the response, not just req.ctx
- scripts/web-app-accept.sh: three new gate legs -- threshold (N pass,
  N+1th 429), SIGTERM+restart (still limited from the WAL), and N
  genuinely-parallel curl clients on one key with an exact-count assertion

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit a653dd0aa64711c43461126d32b4632cc8f64c7a)
2026-09-15 01:15:30 +02:00
..
idempotent.wo feat(porch-store): add digest column to IdempotencyKey table 2026-09-15 01:15:30 +02:00
keypool.wo fix(porch-store): correct reset_at unit on the two fresh-window paths 2026-09-15 01:15:30 +02:00
limiter.wo feat(porch-store): limiter delegates all counting to the key pool 2026-09-15 01:15:30 +02:00
store.wo feat(porch-store): add digest column to IdempotencyKey table 2026-09-15 01:15:30 +02:00