fix(kit): refund rejected replay attempts - #273
Conversation
Refund the per-payload replay token only when the in-flight capacity guard returns SERVICE_BUSY before verification starts. Preserve charges for accepted work, including downstream 503 responses, and cover the behavior with integration tests. Record that routine production docs deploys are manual and do not create a Docs GitHub Release.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughThe PR refunds replay capacity when verification requests are rejected before slot allocation. It adds integration tests and updates operations documentation. It also separates routine documentation deployment from specification releases and adds deployment verification guidance. ChangesReplay capacity handling
Documentation deployment guidance
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PreviewLocally rendered IAPKit Operations documentation showing the replay-budget behavior for 503 SERVICE_BUSY. replay-budget-preview.mp4 |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/kit/src/pages/docs/sections/operations.tsx`:
- Around line 59-62: Update the documentation around X-Concurrency-Scope to
clarify that capacity-rejected requests may access the replay guard’s bucket
store and have their token refunded, but never reach an upstream verification
store; preserve the SERVICE_BUSY versus DUPLICATE_PAYLOAD behavior description.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: cd261260-82d7-48e9-b5be-8d6b4a9fd585
📒 Files selected for processing (9)
.claude/guides/07-docs-package.md.claude/guides/08-deployment.mdknowledge/_claude-context/context.mdknowledge/internal/06-git-deployment.mdpackages/kit/server/api/v1/in-flight-limit.tspackages/kit/server/api/v1/replay-guard.integration.test.tspackages/kit/server/api/v1/replay-guard.tspackages/kit/server/api/v1/routes.tspackages/kit/src/pages/docs/sections/operations.tsx
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
There was a problem hiding this comment.
Pull request overview
This PR adjusts IAPKit’s /v1/purchase/verify replay-budget behavior so that requests rejected before receiving verification capacity (503 SERVICE_BUSY from the in-flight limiter) do not consume a per-payload replay token, while preserving replay charges for requests that were admitted to capacity (including downstream 503s). It also documents the operational implications for docs deployment and the updated replay-budget semantics.
Changes:
- Propagate an in-flight capacity rejection signal (
verifyCapacityRejected) so the outer replay guard can refund the consumed replay token forSERVICE_BUSYrejections. - Add integration tests covering capacity rejection refunds, successful verification charges, and downstream
503behavior after capacity acceptance. - Update operations + deployment documentation to clarify replay-budget semantics and that routine docs deployment is manual and should not create a routine Docs GitHub Release.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| packages/kit/src/pages/docs/sections/operations.tsx | Documents that capacity rejections don’t consume replay budget and retries remain SERVICE_BUSY. |
| packages/kit/server/api/v1/routes.ts | Updates middleware-order commentary and adds a typed per-request flag for capacity rejections. |
| packages/kit/server/api/v1/replay-guard.ts | Refunds replay tokens when the in-flight limiter rejects with SERVICE_BUSY before verification work starts. |
| packages/kit/server/api/v1/replay-guard.integration.test.ts | Adds integration tests for refund vs. charge behavior across capacity rejection and downstream failures. |
| packages/kit/server/api/v1/in-flight-limit.ts | Sets verifyCapacityRejected on capacity rejections so the replay guard can refund the attempt. |
| knowledge/internal/06-git-deployment.md | Clarifies manual docs deployment, merge-vs-deploy expectations, and “no routine docs GitHub Release” policy. |
| knowledge/_claude-context/context.md | Regenerates compiled context to reflect updated deployment documentation. |
| .claude/guides/08-deployment.md | Updates deployment surface matrix to distinguish routine docs deploys vs spec releases. |
| .claude/guides/07-docs-package.md | Aligns docs package guidance with the manual deploy / no-routine-release policy. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Summary
503 SERVICE_BUSY503responsesImplementation
503behavior with integration testsDeployment note
After this PR is merged, deploy routine production docs manually from a clean, up-to-date
maincheckout withnpm run deploy. Do not create a routine Docs GitHub Release;release.ymlremains for an actual spec release or an explicit maintainer request.No deployment, release, or merge is performed by this PR.
Preview
See the
Previewcomment for a short recording of the locally rendered IAPKit Operations page.Test plan
bun install --frozen-lockfilebun run --filter @hyodotdev/openiap-kit lintbun run --filter @hyodotdev/openiap-kit test(75 files, 884 tests)bun run --filter @hyodotdev/openiap-kit smoke:serverbun run audit:paritybun run audit:docsnode --test scripts/release-branch-policy.test.mjsbun run audit:release-state$review-selfsnapshots separated by five minutesSummary by CodeRabbit
Bug Fixes
SERVICE_BUSYinstead of incorrectly becomingDUPLICATE_PAYLOAD.503responses.Documentation