KamoCRM

Give a public chat's own turns the message rate limit, not the session one

FixAPIService
Se descapó
28 de septiembre de 2026 a las 5:02 UTC
Autor
Kamo
Compromit
ef06239

Every public-chat path lives under /sessions/, so the limiter's contains("sessions") test put the conversation itself on the session-creation budget: 3 requests a minute per IP (10 per key), counted against **************** The chat widget is gaining a hands-free spoken mode (listen, send, read the reply aloud, listen again), and a spoken conversation reaches its fourth turn inside a minute; that turn drew a 429 plus an escalating IP cooldown that also blocked every other public-chat call from the address. A conversation's own traffic (sending a turn, reading its history, translating one of its messages) now takes the message tier (30/min per IP, 120 per key). Only paths that CREATE something — /sessions/ai, /sessions/support, /sessions/support/handoff — keep the strict limit that exists to stop bots minting sessions.

Todos los cambios

Como lo que ves enviaste?

Todo llega a su espacio de trabajo por sí solo. Comience en el plan gratuito y lea esta página de nuevo en un mes.

Arranzar gratis para siempreVer Precios