Skip to content

feat: API versioning, rate limit keying + tiering, site.rs docs - #1425

Merged
mftee merged 1 commit into
CodeGirlsInc:mainfrom
ggrunlab-pixel:feature/api-versioning-rate-limit-tiers-site-docs
Sep 28, 2026
Merged

mftee merged 1 commit into
CodeGirlsInc:mainfrom
ggrunlab-pixel:feature/api-versioning-rate-limit-tiers-site-docs

Conversation

@ggrunlab-pixel

Copy link
Copy Markdown
Contributor

Summary

This PR documents site.rs, introduces API route versioning, and hardens rate limiting with better keying and endpoint-specific tiers.

Changes

Document site.rs purpose — #1360

  • Added doc comments to site.rs explaining its responsibility and how it differs from routes.rs, for new-contributor clarity

API route versioning — #1359

  • Added a /v1-style version prefix to endpoints exposed in routes.rs
  • Future breaking changes can now ship under a new version prefix without affecting existing clients on /v1

Rate limiting beyond IP-based keying — #1355

  • Extended rate_limit.rs so limits are no longer keyed purely by source IP
  • Reduces trivial bypass via IP/proxy rotation

Distinct rate limit tiers for submit vs verify — #1356

  • Added separate, appropriately-scaled limits for the expensive submit endpoint vs the cheaper verify endpoint in rate_limit.rs

Summary

This PR documents site.rs, introduces API route versioning, and hardens rate limiting with better keying and endpoint-specific tiers.

Changes

Document site.rs purpose — #1360

  • Added doc comments to site.rs explaining its responsibility and how it differs from routes.rs, for new-contributor clarity

API route versioning — #1359

  • Added a /v1-style version prefix to endpoints exposed in routes.rs
  • Future breaking changes can now ship under a new version prefix without affecting existing clients on /v1

Rate limiting beyond IP-based keying — #1355

  • Extended rate_limit.rs so limits are no longer keyed purely by source IP
  • Reduces trivial bypass via IP/proxy rotation

Distinct rate limit tiers for submit vs verify — #1356

  • Added separate, appropriately-scaled limits for the expensive submit endpoint vs the cheaper verify endpoint in rate_limit.rs

Summary

This PR documents site.rs, introduces API route versioning, and hardens rate limiting with better keying and endpoint-specific tiers.

Changes

Document site.rs purpose — #1360

  • Added doc comments to site.rs explaining its responsibility and how it differs from routes.rs, for new-contributor clarity

API route versioning — #1359

  • Added a /v1-style version prefix to endpoints exposed in routes.rs
  • Future breaking changes can now ship under a new version prefix without affecting existing clients on /v1

Rate limiting beyond IP-based keying — #1355

  • Extended rate_limit.rs so limits are no longer keyed purely by source IP
  • Reduces trivial bypass via IP/proxy rotation

Closes

Closes #1346
Closes #1345
Closes #1351
Closes #1352

Distinct rate limit tiers for submit vs verify — #1356

  • Added separate, appropriately-scaled limits for the expensive submit endpoint vs the cheaper verify endpoint in rate_limit.rs

Testing

  • Confirmed all existing endpoints respond correctly under the new /v1 prefix; checked for any hardcoded old paths in tests/clients
  • Verified rate limiting can no longer be bypassed by rotating IPs alone (tested with new keying approach)
  • Verified submit and verify are limited independently and at their intended thresholds
  • Confirmed site.rs doc comments render correctly and accurately describe its scope vs routes.rs

Closes

Closes #1347
Closes #1348
Closes #1358
Closes #1357

Testing

  • Confirmed all existing endpoints respond correctly under the new /v1 prefix; checked for any hardcoded old paths in tests/clients
  • Verified rate limiting can no longer be bypassed by rotating IPs alone (tested with new keying approach)
  • Verified submit and verify are limited independently and at their intended thresholds
  • Confirmed site.rs doc comments render correctly and accurately describe its scope vs routes.rs

Closes

Closes #1350
Closes #1349
Closes #1353
Closes #1354

Testing

  • Confirmed all existing endpoints respond correctly under the new /v1 prefix; checked for any hardcoded old paths in tests/clients
  • Verified rate limiting can no longer be bypassed by rotating IPs alone (tested with new keying approach)
  • Verified submit and verify are limited independently and at their intended thresholds
  • Confirmed site.rs doc comments render correctly and accurately describe its scope vs routes.rs

Closes

Closes #1360
Closes #1359
Closes #1355
Closes #1356

- Document site.rs purpose and its responsibility split from routes.rs
- Add /v1-style version prefix to API routes
- Extend rate limiting beyond pure IP-based keying
- Add distinct rate limit tiers for submit vs verify endpoints

Closes CodeGirlsInc#1360
Closes CodeGirlsInc#1359
Closes CodeGirlsInc#1355
Closes CodeGirlsInc#1356
@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

@ggrunlab-pixel is attempting to deploy a commit to the Mftee's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@ggrunlab-pixel Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@mftee
mftee merged commit 381ba47 into CodeGirlsInc:main Sep 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment