Skip to content

fix(api): mitigate Cloudflare 403 blocks with paced requests, retries, and browser headers - #203

Open
bnku wants to merge 1 commit into
Lampese:mainfrom
bnku:fix/cloudflare-403-rate-limit
Open

bnku wants to merge 1 commit into
Lampese:mainfrom
bnku:fix/cloudflare-403-rate-limit

Conversation

@bnku

@bnku bnku commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

When multiple accounts are refreshed on startup or via the refresh action, the application previously fired concurrent batches (up to 10 parallel requests) to both chatgpt.com/backend-api/wham/usage and chatgpt.com/backend-api/accounts/check/v4-2023-04-27. Cloudflare's bot-detection WAF treats sudden concurrent bursts as bot scraping, triggering a 403 Forbidden ("Unable to load site") challenge and temporarily blocking subsequent requests from the client IP across all accounts.

In addition, account_stats.rs was still sending User-Agent: codex-cli/1.0.0 without browser-like headers (which was previously updated in usage.rs via #110).

Changes

  1. Request Pacing & Reduced Concurrency:
    • Reduced concurrent usage requests in useAccounts.ts from 10 to 2 with a 150ms delay between consecutive requests.
    • Paced refreshMetadata requests sequentially (concurrency 1 with 250ms delay) to avoid tripping the sensitive accounts/check endpoint.
    • Capped refresh_all_usage and warmup_all_accounts concurrency in the Rust backend to 2.
  2. Sequential Refresh Flow:
    • Sequenced usage updates and metadata updates on startup and during manual refresh rather than issuing them simultaneously across endpoints.
  3. Transient 403 Backoff & Retry:
    • Added a single 750ms backoff and retry for 403 responses in get_usage_with_chatgpt_auth and fetch_chatgpt_account_metadata without rotating/burning the refresh token.
  4. Header Alignment:
    • Updated build_chatgpt_headers in commands/account_stats.rs to send BROWSER_USER_AGENT and standard browser headers (Accept-Language, Origin, Referer, sec-fetch-*).
  5. Clear Error Message:
    • Surfaced a user-friendly error message (Rate limited by Cloudflare (403). Try again in a moment.) instead of generic API error: 403 Forbidden.

…, and browser headers

- Reduce concurrent usage and metadata requests to prevent Cloudflare burst rate limiting
- Add pacing/delays between account requests during batch refresh
- Sequence usage updates and metadata updates instead of issuing them in parallel
- Add single 750ms backoff and retry for transient 403 responses in usage and metadata endpoints
- Update account_stats.rs to use browser user agent and standard browser headers
- Provide a clear, actionable error message when Cloudflare rate limits requests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant