Skip to content

Cherry-pick f943c76cd: security(feishu): bound unauthenticated webhook rate-limit state#1447

Merged
alexey-pelykh merged 1 commit intomainfrom
cherry-pick/f943c76cd-feishu-webhook-ratelimit
Mar 15, 2026
Merged

Cherry-pick f943c76cd: security(feishu): bound unauthenticated webhook rate-limit state#1447
alexey-pelykh merged 1 commit intomainfrom
cherry-pick/f943c76cd-feishu-webhook-ratelimit

Conversation

@alexey-pelykh
Copy link
Copy Markdown

Cherry-pick of upstream openclaw/openclaw@f943c76cd.

security(feishu): bound unauthenticated webhook rate-limit state (openclaw#26050) thanks @bmendonca3

Bounds the in-memory rate-limit map for unauthenticated webhook requests to prevent unbounded memory growth from spoofed sender IDs.

Resolves part of #678.

Cherry-picked-from: f943c76

…nclaw#26050) thanks @bmendonca3

Verified:
- pnpm install --frozen-lockfile
- pnpm build
- pnpm check
- pnpm test:macmini

Co-authored-by: bmendonca3 <[email protected]>
Co-authored-by: Tak Hoffman <[email protected]>
(cherry picked from commit f943c76)
@alexey-pelykh alexey-pelykh merged commit 99c252e into main Mar 15, 2026
7 checks passed
@alexey-pelykh alexey-pelykh deleted the cherry-pick/f943c76cd-feishu-webhook-ratelimit branch March 15, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants