• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 31860777326
95%

Build:
DEFAULT BRANCH: main
Ran 15 Aug 2026 03:06AM UTC
Jobs 1
Files 89
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Aug 2026 03:02AM UTC coverage: 94.12% (-0.06%) from 94.175%
31860777326

push

github

web-flow
feat: Rate-limit the public DIDComm passthrough in Drawbridge (#889)

* feat: Rate-limit the public DIDComm passthrough in Drawbridge

Drawbridge proxies the DIDComm relay at /didcomm as a public passthrough,
registered ahead of the authenticated /api/v1 router with nothing in front
of it. Two routes behind it are unauthenticated by design and cannot be
otherwise: a sender must be able to reach a stranger's mailbox, and
GET /challenge is the first step of proving DID control.

#887 capped storage, which bounds where a flood stops. It does not bound
how fast one gets there -- with a 10mb body limit on this side, the 256MB
default cap is reachable in a couple of dozen requests -- and once storage
is full the relay answers 429 to legitimate senders too, for as long as an
attacker keeps it full.

Add a limiter with two buckets, because neither works alone. Per-source is
meaningful on clearnet only: over Tor every request arrives from the local
daemon and shares one source, and trust proxy is not configured, so behind
a reverse proxy the source is the proxy. A global bucket is the backstop
that holds in both cases. It is blunt -- during a flood it turns away
legitimate senders too -- but that is better than the alternative, where
they are refused anyway once storage is full, and for longer.

Reuses the existing sliding-window limiter. Its key argument is named
`did` but is treated as an opaque string, so nothing new was needed in the
store; the buckets are namespaced by surface so a second passthrough can
adopt this without sharing a bucket.

Defaults assume one poll costs four requests (challenge, fetch, challenge,
remove), so 300/minute per source clears an active wallet comfortably,
with 3000/minute globally.

Fails open if the limiter's own store is unreachable. It exists to protect
availability, so refusing every request would cause the outage it prevents,
and the storage caps still bound growth underneath.

Tests cover pass-through under the limits, ... (continued)

3743 of 4212 branches covered (88.87%)

Branch coverage included in aggregate %.

47 of 52 new or added lines in 2 files covered. (90.38%)

8391 of 8680 relevant lines covered (96.67%)

680.26 hits per line

Uncovered Changes

Lines Coverage ∆ File
4
87.39
services/drawbridge/server/src/middleware/public-rate-limit.ts
1
90.0
5.63% services/drawbridge/server/src/config.ts
Jobs
ID Job ID Ran Files Coverage
1 31860777326.1 15 Aug 2026 03:06AM UTC 178
95.14
GitHub Action Run
Source Files on build 31860777326
  • Tree
  • List 89
  • Changed 74
  • Source Changed 1
  • Coverage Changed 74
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #31860777326
  • 280c404c on github
  • Prev Build on main (#31848665615)
  • Next Build on main (#31891964958)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc