| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | fix(hub): rate-limit per client, not per proxy | Christophe Besson | 2 days | 1 | -3/+7 |
| | | | | | | | | | | | | Behind Caddy every request's TCP peer is loopback, and the limiter was keyed on that peer (slowapi's get_remote_address), so each limit was one bucket for the whole internet: ten node sign-ins a minute shared by every node. A node starting while others signed in got 429 and sat in waiting_for_hub, which the desktop app took for no node at all. Key it on client_ip, which already resolves X-Forwarded-For from a trusted proxy and was written for this. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> | ||||
| * | feat(hub): add production hub — config, auth, API routers, tests | Christophe Besson | 2026-08-09 | 1 | -0/+13 |
| config.py: TOML + env var priority. auth.py: Argon2id passwords, JWT EdDSA with jti, refresh token hashed (blake3). Routers: hub (info/pubkey), users (register/login/refresh/pubkeys), nodes (announce/get), groups (create/gek-bundle/gek-retrieve). Rate limiting via slowapi. app.py factory with lifespan. All 40 tests pass (SQLite in-memory, no PostgreSQL required). Fix: remove tests/__init__.py to resolve namespace conflicts. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com> | |||||