Skip to content

feat: respect server rate-limit headers and surface quota in UI - #1110

Open
martoniel wants to merge 3 commits into
Nanle-code:masterfrom
martoniel:feat/server-rate-limit-headers
Open

martoniel wants to merge 3 commits into
Nanle-code:masterfrom
martoniel:feat/server-rate-limit-headers

Conversation

@martoniel

@martoniel martoniel commented Sep 28, 2026 •

Copy link
Copy Markdown

Closes #842


  • Add parseRateLimitHeaders() to stellar.ts: parses X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset, and Retry-After from every HTTP response into a typed RateLimitQuota snapshot. Missing or non-numeric header values are safely coerced to null.

  • Wire _updateQuotaFromResponse() into rateLimitedFetch so both the immediate and queued code paths push the latest quota to the store after every response, including 429s.

  • Add RateLimitQuota interface and rateLimitQuota / setRateLimitQuota slice to the Zustand store (store.ts). Starts null; updated on every API response that carries rate-limit headers.

  • Add RateLimitQuotaDisplay component: shows remaining/limit counts, an accessible progress bar (green/amber/red), reset time, and a rate-limited warning state. Renders nothing until the first quota snapshot arrives.

  • Add rateLimitHeaders.test.ts (15 tests): primary flow, boundary case (429 with Retry-After only), failure cases (malformed/missing headers), and store integration tests. All 15 pass.

Summary

Closes #

How was this tested?

Merge requirements

A PR is merged only when every box below is true. See
Merge requirements for the full policy.

  • All required CI checks pass on the latest commit (not just an earlier push).
  • No required checks are failing, pending, or skipped — re-run or fix them; do not ask for a merge while any are outstanding.
  • The branch has no merge conflicts with the target branch (rebase or merge master if GitHub shows "This branch has conflicts").
  • Tests were added or updated for the change (primary flow, a boundary case, and a failure case).
  • Docs were updated where behaviour, configuration, or security posture changed.

Security-sensitive changes

  • This PR touches a path covered by .github/CODEOWNERS (wallet, auth, cryptography, CI) and a code owner has been requested for review.
  • I described any change to key handling, signing, session lifetime, or trusted endpoints above.

- Add parseRateLimitHeaders() to stellar.ts: parses X-RateLimit-Limit,
  X-RateLimit-Remaining, X-RateLimit-Reset, and Retry-After from every
  HTTP response into a typed RateLimitQuota snapshot. Missing or
  non-numeric header values are safely coerced to null.

- Wire _updateQuotaFromResponse() into rateLimitedFetch so both the
  immediate and queued code paths push the latest quota to the store
  after every response, including 429s.

- Add RateLimitQuota interface and rateLimitQuota / setRateLimitQuota
  slice to the Zustand store (store.ts). Starts null; updated on every
  API response that carries rate-limit headers.

- Add RateLimitQuotaDisplay component: shows remaining/limit counts,
  an accessible progress bar (green/amber/red), reset time, and a
  rate-limited warning state. Renders nothing until the first
  quota snapshot arrives.

- Add rateLimitHeaders.test.ts (15 tests): primary flow, boundary case
  (429 with Retry-After only), failure cases (malformed/missing headers),
  and store integration tests. All 15 pass.
@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@martoniel is attempting to deploy a commit to the nanle-code's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@martoniel Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Manuelshub

Copy link
Copy Markdown
Collaborator

@martoniel Please resolve conflicts.

@martoniel

Copy link
Copy Markdown
Author

@Manuelshub I have resolved conflicts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[2026 Security] Add rate-limit aware client backoff for dashboard API proxies

2 participants