+2
.claude/commands/status-update.md
+2
.claude/commands/status-update.md
+12
-1
STATUS.md
+12
-1
STATUS.md
···
47
47
48
48
### December 2025
49
49
50
+
#### rate limit moderation endpoint (PR #629, Dec 21)
51
+
52
+
**incident response**: detected suspicious activity - 72 requests in 17 seconds from a single IP targeting `/moderation/sensitive-images`. investigation via Logfire showed:
53
+
- single IP generating all traffic with no User-Agent header
54
+
- requests spaced ~230ms apart (too consistent for human browsing)
55
+
- no corresponding user activity (page loads, audio streams)
56
+
57
+
**fix**: added `10/minute` rate limit to the endpoint using existing slowapi infrastructure. verified rate limiting works correctly post-deployment.
58
+
59
+
---
60
+
50
61
#### end-of-year sprint (Dec 20-31)
51
62
52
63
**focus**: two foundational systems need solid experimental implementations by 2026.
···
540
551
541
552
---
542
553
543
-
this is a living document. last updated 2025-12-20.
554
+
this is a living document. last updated 2025-12-21.