Skip to content

🐛 Ignore pollInterval and pollDebounce from clients - #750

Merged
alecgibson merged 1 commit into
mainfrom
ignore-client-poll-options
Oct 8, 2026
Merged

alecgibson merged 1 commit into
mainfrom
ignore-client-poll-options

Conversation

@alecgibson

Copy link
Copy Markdown
Collaborator

Fixes #734

At the moment, QueryEmitter prefers pollInterval and pollDebounce from the query options over the database's own, and those options come straight from the client, so a client can lift the server's poll rate limit:

  1. Set db.pollDebounce = 5000
  2. Subscribe 50 queries with {pollInterval: 1, pollDebounce: 0}
  3. The database gets ~35,000 polls per second

This change strips both keys from client query options in the Agent, before query middleware runs. Apps that set them from a Connection should set them on the database adapter instead, or map their own option onto context.options in query middleware.

🤖 Generated with Claude Code

Co-Authored-By: Claude noreply@anthropic.com

@coveralls

coveralls commented Oct 8, 2026 •

Copy link
Copy Markdown

Coverage Status

coverage: 97.852% (+0.001%) from 97.851% — ignore-client-poll-options into main

Fixes #734

At the moment, `QueryEmitter` prefers `pollInterval` and `pollDebounce`
from the query options over the database's own, and those options come
straight from the client, so a client can lift the server's poll rate
limit:

 1. Set `db.pollDebounce = 5000`
 2. Subscribe 50 queries with `{pollInterval: 1, pollDebounce: 0}`
 3. The database gets ~35,000 polls per second

This change strips both keys from client query options in the `Agent`,
before `query` middleware runs. Apps that set them from a `Connection`
should set them on the database adapter instead, or map their own
option onto `context.options` in `query` middleware.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused implementation addresses the rate-limit bypass and is adequately tested and documented.

0 open findings

What changed in this PR

Prevents clients from overriding server-controlled query polling limits.

Changes:

  • Strips client-provided pollInterval and pollDebounce before middleware.
  • Updates polling tests to configure trusted values server-side.
  • Documents the new behavior.
File Description
lib/​agent.js Removes unsafe client polling options.
test/​client/​query-subscribe.js Tests filtering and server-side configuration.
docs/​middleware/​actions.md Documents middleware behavior.
docs/​api/​connection.md Documents ignored client options.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@alecgibson
alecgibson requested a review from dawidreedsy October 8, 2026 13:51
@alecgibson
alecgibson marked this pull request as ready for review October 8, 2026 13:51
@alecgibson
alecgibson merged commit ad54aa4 into main Oct 8, 2026
10 checks passed
@alecgibson
alecgibson deleted the ignore-client-poll-options branch October 8, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Client-supplied pollInterval/pollDebounce override the server's DB query rate limit

4 participants