[E24-S02] Rate limits #148

Open
opened 2026-08-27 00:04:39 +00:00 by kpcto · 0 comments
Owner

Parent epic: [E24] Security (#52)

Intent

Login and abuse-prone mutation routes have documented rate limits and configuration.

Acceptance criteria

  • The login route has a documented rate limit.
  • Abuse-prone mutation routes have documented limits and configuration.
  • Rate limits are configurable rather than hard-coded only.

Explicitly out of scope

  • Threat model (E24-S01) and CSP/security headers (E24-S03).
  • Dependency/security response process (E24-S04).

Test plan

  • Automated test asserting the rate limit triggers on login and mutation routes.

Rollback note

  • No data change; reverting limit configuration restores prior behaviour.

Owning stream

platform

Risk quadrant

agent-full

> Parent epic: [E24] Security (#52) ## Intent Login and abuse-prone mutation routes have documented rate limits and configuration. ## Acceptance criteria - The login route has a documented rate limit. - Abuse-prone mutation routes have documented limits and configuration. - Rate limits are configurable rather than hard-coded only. ## Explicitly out of scope - Threat model (E24-S01) and CSP/security headers (E24-S03). - Dependency/security response process (E24-S04). ## Test plan - Automated test asserting the rate limit triggers on login and mutation routes. ## Rollback note - No data change; reverting limit configuration restores prior behaviour. ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 7 milestone 2026-08-27 00:04:39 +00:00
kpcto added the
status
proposed
kind
story
labels 2026-08-27 00:04:39 +00:00
Sign in to join this conversation.