KamoCRM

Give a public chat's own turns the message rate limit, not the session one

FixAPIService
Ya
28 Septemba 2026, 05:02 UTC
Mwandishi
Kamo
Ahadi ya
ef06239

Every public-chat path lives under /sessions/, so the limiter's contains("sessions") test put the conversation itself on the session-creation budget: 3 requests a minute per IP (10 per key), counted against **************** The chat widget is gaining a hands-free spoken mode (listen, send, read the reply aloud, listen again), and a spoken conversation reaches its fourth turn inside a minute; that turn drew a 429 plus an escalating IP cooldown that also blocked every other public-chat call from the address. A conversation's own traffic (sending a turn, reading its history, translating one of its messages) now takes the message tier (30/min per IP, 120 per key). Only paths that CREATE something — /sessions/ai, /sessions/support, /sessions/support/handoff — keep the strict limit that exists to stop bots minting sessions.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila kitu kinaingia kwenye tovuti yako mwenyewe. Anza kwenye mpango wa bure na usome ukurasa huu tena katika mwezi mmoja.

Kuwa Huru MileleMtazamo wa bei