Skip to content

security(backend): add abuse controls and correlation IDs to mutation routes #131

Description

@arisu6804

Problem

High-volume retries or automated abuse can exhaust provider quotas and make incidents hard to trace.

Objective

Deliver a production-quality improvement to transfer, quote, and administrative mutation routes that creates measurable value for correctness, security, reliability, performance, or maintainability.

Implementation scope

  • Add route-specific actor/client limits, safe 429 behavior, correlation propagation, and bounded limiter state.

Acceptance criteria

  • Mutation routes have documented limits; abusive bursts are bounded; every accepted command can be correlated without leaking account data.

Required validation

  • Burst, identity isolation, proxy trust, 429, correlation, and load tests.
  • Existing tests and CI remain passing.
  • Add regression coverage for the original failure mode.
  • Do not weaken, delete, or skip unrelated tests to obtain a green build.

PR quality bar

  • Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
  • Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.

Out of scope

  • Broad rewrites not required by the acceptance criteria.
  • Changes to unrelated services, contracts, or user flows.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    GRANTFOX OSSOpen-source issue tracked by GrantFoxMAYBE REWARDEDThis issue may carry a rewardThird CampaignThird Campaign contributionenhancementNew feature or requestpriority:highHigh implementation priority

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions