Skip to content

馃敡(dev-instance) raise the document access throttle for the history panel - #8

Merged
YousefED merged 1 commit into
devfrom
fix/dev-instance-access-throttle
Oct 9, 2026
Merged

YousefED merged 1 commit into
devfrom
fix/dev-instance-access-throttle

Conversation

@YousefED

@YousefED YousefED commented Oct 9, 2026

Copy link
Copy Markdown

Problem

The history panel often failed with 503 errors.

  • yhub checks the access of each history request with the backend, through /api/v1.0/documents/<id>/accesses/me/.
  • The backend throttles this endpoint to 50 requests per minute for each user (API_DOCUMENT_ACCESS_THROTTLE_RATE, upstream default).
  • When you click through the history panel, each version needs some requests (content, baseline, attributions). Thus, a user quickly gets more than 50 requests in a minute.
  • The backend then answers 429 ("Too Many Requests"). yhub then answers 503 ("Document authorization backend is unavailable").

The backend log showed many "Too Many Requests" warnings for accesses/me/ at the same times as the 503 errors in the frontend log.

Change

deploy/dev-instance/compose.yaml: the dev instance sets API_DOCUMENT_ACCESS_THROTTLE_RATE and API_DOCUMENT_THROTTLE_RATE to 1000/minute. Production defaults do not change.

Note for the versioning work

With the upstream default, the history panel can fail for normal use. Upstream Docs probably needs a higher limit for the access check that yhub makes, or yhub must cache the result of the access check.

yhub checks the access of each history request with the backend
(/documents/<id>/accesses/me/). The default throttle of 50 requests per
minute for each user made the backend answer 429, and yhub then answered
503. Clicking through the history panel reached this limit quickly.

Signed-off-by: yousefed <yousefdardiry@gmail.com>
@YousefED
YousefED merged commit edad5cc into dev Oct 9, 2026
18 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant