Skip to content

api(stats): every anonymous stats request loads the full repo inventory and all visibility rules #485

Description

@euxaristia

Summary

GET /api/v1/stats (crates/gitlawb-node/src/server.rs:546-579, on meta_routes with no auth layer or limiter) calls list_all_repos_deduped() (no LIMIT, db/mod.rs:1525) and then list_visibility_rules_for_repos(&ids) (db/mod.rs:4121) on every request, JSON-parsing every reader_dids list to produce one integer. A byte-budgeted variant built for anonymously reachable surfaces, list_visibility_rules_for_repos_bounded (db/mod.rs:4183), exists but is not used here.

Impact

Every anonymous request performs a full inventory transfer and allocation (repos plus all visibility rules, the latter owner-inflatable via rule flooding), multiplied by parallel callers. Cost grows with total inventory, so the endpoint gets slower and heavier for its entire life with no cache, limit, or admission.

Remediation

  1. Use the bounded rules variant (or a count-only query) for this endpoint.
  2. Cache the count briefly or admit the route.

Proposed labels: kind:security, crate:node, subsystem:api.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surface

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions