Repository navigation
feat(nip-01): add rate-limited backoff hint to OK messages - #807
Conversation
🦋 Changeset detectedLatest commit: 618bfd9 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
|
From Muse: Independent check of the math: the EWMA decay ( |
chappie-daemon
left a comment
There was a problem hiding this comment.
Reviewed (chappie-daemon). Approved.
Verified against the proposal this implements (nostr-protocol/nips#2498, still OPEN): the fifth param is an optional zero-free decimal string of a positive integer in milliseconds, MAY be approximate, and its absence MUST NOT be read as an instruction to retry immediately. The implementation matches on every point I could test:
- The hint is the tripped window's
period(ms) viaMath.max(1, Math.ceil(period))— always a positive, zero-free integer, approximate by construction (a sliding window's true wait depends on when old events age out; EWMA decays continuously), which the proposal explicitly permits. Sent as a string (String(rateLimited)), matching the spec's decimal-string form. - Fail-closed path returns
truerather than a number, so the param is omitted — and the NIP's 'absence MUST NOT be read as retry immediately' makes that safe. - Only one
rate-limitedOK sender exists (event-message-handler); the connection-level limiter in web-socket-server-adapter terminates the socket without a protocol message and is untouched, so the 'CLOSED is untouched' claim in the body is accurate. - Backward compatible: the 4-element form is unchanged when no hint exists; positional clients reading [0..3] see no difference.
Ran the branch (618bfd9): pnpm run test:unit 2116 passing / 0 failing, pnpm run lint clean (biome, 492 files), pnpm run build:check (tsc --noEmit) clean. Changeset is a correct minor.
One observation, not a finding: period has no >0 validation for limits.event.rateLimits in settings-config.ts (only pow.periodMs is validated), so a misconfigured period of 0 would surface as a 1ms hint after the Math.max(1, ...) clamp. The clamp keeps the protocol value valid regardless; noting it only because a settings guard could be a cheap follow-up.
Description
Implements the optional NIP-01
rate-limitedbackoff param (nostr-protocol/nips#2498).When an event is rate-limited, the relay now sends:
["OK", , false, "rate-limited: slow down", ""]
period(ms) of the rate-limit window that tripped: a conservative, approximate hint as the NIP allows, so it works for both EWMA and sliding-window limiters with no limiter or config changes.createCommandResult/createEventCommandResultaccept an optional trailingparams; the 4-element form is unchanged for all other OK messages.CLOSEDis untouched, since nostream never sendsrate-limitedon it.Related Issue
Closes :- #805
Motivation and Context
How Has This Been Tested?
isRateLimitedreturns the tripped period,createCommandResultwith params.pnpm run lint,pnpm run build:check,pnpm run test:unitall pass.Screenshots (if appropriate):
Types of changes
Checklist: