Agent proxy has no quota, rate limit or token cap #51

Open
opened 2026-09-05 15:03:44 +00:00 by ImBenji · 0 comments
Owner

backend/lib/src/agent_proxy.dart requires a session and pins the model server-side, so a modified client cannot pick a more expensive one. That is where the protection stops.

There is no per-user quota, no rate limit, no token accounting and no max_tokens clamp - greps for quota, ratelimit, throttle and limit across backend/lib and backend/bin return nothing. Message size, max_tokens and request frequency are all client-controlled, and the OpenRouter key is yours.

So any account that can sign in can run unbounded inference spend, and nothing in the system would report it until the bill did. Sign-up is OIDC, so "an account" is not a high bar.

This is a live financial hole rather than a theoretical one, and it is the same metering code the paid AI tier needs, so it is not throwaway work. STRATEGY.md section 11 sizes it at 15-25 hrs.

Minimum worth having:

  • per-account request and token budget over a rolling window, persisted alongside the session
  • a server-side max_tokens ceiling that overwrites whatever the client sent, same way model already is
  • a request body size cap, since the scene serialiser can produce a big payload on a large map
  • usage recorded per account so the number is knowable before it is a surprise

Found during the roadmap audit on 2026-09-05. Nothing on the board covered it.

`backend/lib/src/agent_proxy.dart` requires a session and pins the model server-side, so a modified client cannot pick a more expensive one. That is where the protection stops. There is no per-user quota, no rate limit, no token accounting and no `max_tokens` clamp - greps for `quota`, `ratelimit`, `throttle` and `limit` across `backend/lib` and `backend/bin` return nothing. Message size, `max_tokens` and request frequency are all client-controlled, and the OpenRouter key is yours. So any account that can sign in can run unbounded inference spend, and nothing in the system would report it until the bill did. Sign-up is OIDC, so "an account" is not a high bar. This is a live financial hole rather than a theoretical one, and it is the same metering code the paid AI tier needs, so it is not throwaway work. STRATEGY.md section 11 sizes it at 15-25 hrs. Minimum worth having: - per-account request and token budget over a rolling window, persisted alongside the session - a server-side `max_tokens` ceiling that overwrites whatever the client sent, same way `model` already is - a request body size cap, since the scene serialiser can produce a big payload on a large map - usage recorded per account so the number is knowable before it is a surprise Found during the roadmap audit on 2026-09-05. Nothing on the board covered it.
ImBenji added this to the Arcs & Angles project 2026-09-05 15:03:44 +00:00
ImBenji added the bug label 2026-09-05 15:14:12 +00:00
ImBenji added the area:performance label 2026-09-05 15:15:15 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: IMBENJI.NET/Metro-Map-Maker#51