• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / lifelines / 32045079843
95%

Build:
DEFAULT BRANCH: main
Ran 17 Aug 2026 04:19PM UTC
Jobs 1
Files 7
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Aug 2026 04:19PM UTC coverage: 94.562% (-0.2%) from 94.805%
32045079843

push

github

web-flow
fix: throttle the public lookup endpoint per client (#49)

The search endpoint is registered for wp_ajax_nopriv and, by design,
takes no nonce — it serves read-only public data and a nonce would go
stale behind full-page caching. Nothing bounded how often it could be
called, and every call runs a LIKE '%term%' scan across every searchable
column, where a leading wildcard means no index helps. Cheap once,
expensive in a loop.

A fixed-window per-IP counter now sits in front of it, checked before
the term is read so a refused caller costs one transient read and never
reaches the scan.

The ceiling is deliberately loose — 300 requests a minute — and every
choice here errs towards letting the request through:

  - This backs a helpline finder. Someone using it may be in a bad way,
    and a lookup that refuses to answer is a worse outcome than a
    database working harder than it needs to.
  - The front end debounces at 200ms, so a continuous minute of typing
    stays far below the cap.
  - clientIp() reads REMOTE_ADDR only, never X-Forwarded-For, which the
    caller controls and could use to mint a fresh bucket per request.
    Behind a CDN that means the edge address, so a whole town may share
    one bucket — the cap is sized assuming it does.

Precise per-visitor limiting belongs at the CDN or WAF, which can see
the real client. This is a floor, not that.

The constructor argument is optional so existing callers are unaffected;
there is one sensible implementation and nothing to configure. The
controller's tests now clear transients between cases, since the
endpoint keeps state per client where it previously kept none.

22 of 24 new or added lines in 2 files covered. (91.67%)

313 of 331 relevant lines covered (94.56%)

3.09 hits per line

Uncovered Changes

Lines Coverage ∆ File
2
88.24
src/Lookup/RateLimiter.php
Jobs
ID Job ID Ran Files Coverage
1 32045079843.1 17 Aug 2026 04:19PM UTC 7
94.56
GitHub Action Run
Source Files on build 32045079843
  • Tree
  • List 7
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32045079843
  • a10647eb on github
  • Prev Build on main (#31960710213)
  • Next Build on main (#32057165987)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc