backend/lib/src/agent_proxy.dart requires a session and pins the model server-side, so a modified client cannot pick a more expensive one. That is where the protection stops.
There is no per-user quota, no rate limit, no token accounting and no max_tokens clamp - greps for quota, ratelimit, throttle and limit across backend/lib and backend/bin return nothing. Message size, max_tokens and request frequency are all client-controlled, and the OpenRouter key is yours.
So any account that can sign in can run unbounded inference spend, and nothing in the system would report it until the bill did. Sign-up is OIDC, so "an account" is not a high bar.
This is a live financial hole rather than a theoretical one, and it is the same metering code the paid AI tier needs, so it is not throwaway work. STRATEGY.md section 11 sizes it at 15-25 hrs.
Minimum worth having:
per-account request and token budget over a rolling window, persisted alongside the session
a server-side max_tokens ceiling that overwrites whatever the client sent, same way model already is
a request body size cap, since the scene serialiser can produce a big payload on a large map
usage recorded per account so the number is knowable before it is a surprise
Found during the roadmap audit on 2026-09-05. Nothing on the board covered it.
`backend/lib/src/agent_proxy.dart` requires a session and pins the model server-side, so a modified client cannot pick a more expensive one. That is where the protection stops.
There is no per-user quota, no rate limit, no token accounting and no `max_tokens` clamp - greps for `quota`, `ratelimit`, `throttle` and `limit` across `backend/lib` and `backend/bin` return nothing. Message size, `max_tokens` and request frequency are all client-controlled, and the OpenRouter key is yours.
So any account that can sign in can run unbounded inference spend, and nothing in the system would report it until the bill did. Sign-up is OIDC, so "an account" is not a high bar.
This is a live financial hole rather than a theoretical one, and it is the same metering code the paid AI tier needs, so it is not throwaway work. STRATEGY.md section 11 sizes it at 15-25 hrs.
Minimum worth having:
- per-account request and token budget over a rolling window, persisted alongside the session
- a server-side `max_tokens` ceiling that overwrites whatever the client sent, same way `model` already is
- a request body size cap, since the scene serialiser can produce a big payload on a large map
- usage recorded per account so the number is knowable before it is a surprise
Found during the roadmap audit on 2026-09-05. Nothing on the board covered it.
ImBenji
added this to the Arcs & Angles project 2026-09-05 15:03:44 +00:00
ImBenji
added the bug label 2026-09-05 15:14:12 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
backend/lib/src/agent_proxy.dartrequires a session and pins the model server-side, so a modified client cannot pick a more expensive one. That is where the protection stops.There is no per-user quota, no rate limit, no token accounting and no
max_tokensclamp - greps forquota,ratelimit,throttleandlimitacrossbackend/libandbackend/binreturn nothing. Message size,max_tokensand request frequency are all client-controlled, and the OpenRouter key is yours.So any account that can sign in can run unbounded inference spend, and nothing in the system would report it until the bill did. Sign-up is OIDC, so "an account" is not a high bar.
This is a live financial hole rather than a theoretical one, and it is the same metering code the paid AI tier needs, so it is not throwaway work. STRATEGY.md section 11 sizes it at 15-25 hrs.
Minimum worth having:
max_tokensceiling that overwrites whatever the client sent, same waymodelalready isFound during the roadmap audit on 2026-09-05. Nothing on the board covered it.