KamoCRM

Give a public chat's own turns the message rate limit, not the session one

FixAPIService
Shipped
September 28, 2026 at 5:02 AM UTC
Author
Kamo
Commit
ef06239

Every public-chat path lives under /sessions/, so the limiter's contains("sessions") test put the conversation itself on the session-creation budget: 3 requests a minute per IP (10 per key), counted against **************** The chat widget is gaining a hands-free spoken mode (listen, send, read the reply aloud, listen again), and a spoken conversation reaches its fourth turn inside a minute; that turn drew a 429 plus an escalating IP cooldown that also blocked every other public-chat call from the address. A conversation's own traffic (sending a turn, reading its history, translating one of its messages) now takes the message tier (30/min per IP, 120 per key). Only paths that CREATE something — /sessions/ai, /sessions/support, /sessions/support/handoff — keep the strict limit that exists to stop bots minting sessions.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing