P2: RATE_LIMIT_PER_MINUTE env var NaN on invalid input — rate limiting silently disabled #13
Loading…
Reference in New Issue
No description provided.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: P2 — Medium
File: server/index.js ~line 38
Problem: parseInt(process.env.RATE_LIMIT_PER_MINUTE || 5, 10) returns NaN if env var is non-numeric (e.g., abc). Rate limiting silently disabled.
Impact: Rate limiting disabled without warning.
Fix: Add NaN check and fallback to default value with warning log.