From 571f3e9fd8ddbb5630e4ffb127335b957bbce338 Mon Sep 17 00:00:00 2001 From: Owen Qwen Date: Tue, 21 Jul 2026 15:51:16 -0500 Subject: [PATCH] Changing ratelimit --- README.md | 2 +- src/rate-limit.js | 2 +- test/rate-limit.test.js | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 84f27fa..a56eed3 100644 --- a/README.md +++ b/README.md @@ -35,7 +35,7 @@ npm run keys:env The global context limit defaults to 256k tokens and can be changed with `MAX_CONTEXT_TOKENS`. -Inference requests are limited per client IP to 2 requests per second, 100 requests per five hours, and $10 of reported upstream cost per five hours. Railway's `X-Real-IP` header is used to identify clients. +Inference requests are limited per client IP to 2 requests per second, 100 requests per five hours, and $15 of reported upstream cost per five hours. Railway's `X-Real-IP` header is used to identify clients. To exempt trusted clients from those proxy limits, set `UNLIMITED_API_KEYS` to a JSON array and have the client send a configured key using `Authorization: Bearer ` or `x-api-key`. These keys only bypass this proxy's rate and spend limits; they do not bypass upstream OpenCode Go limits. diff --git a/src/rate-limit.js b/src/rate-limit.js index 4f4a652..72ce05b 100644 --- a/src/rate-limit.js +++ b/src/rate-limit.js @@ -4,7 +4,7 @@ const FIVE_HOURS = 5 * 60 * 60 * 1_000; export const RATE_LIMITS = { requestsPerSecond: 2, requestsPerFiveHours: 100, - spendPerFiveHours: 10, + spendPerFiveHours: 15, }; function prune(timestamps, now, window) { diff --git a/test/rate-limit.test.js b/test/rate-limit.test.js index 6267557..c84c07c 100644 --- a/test/rate-limit.test.js +++ b/test/rate-limit.test.js @@ -10,7 +10,7 @@ describe('rate limiter', () => { expect(limiter.check('ip').allowed).toBe(false); time = 1_001; expect(limiter.check('ip').allowed).toBe(true); - limiter.recordCost('ip', 10); + limiter.recordCost('ip', 15); expect(limiter.check('ip').allowed).toBe(false); time = 5 * 60 * 60 * 1_000 + 1_002; expect(limiter.check('ip').allowed).toBe(true);