T
6

Rate limit headers are a suggestion until they aren't

Found out the hard way that our API gateway was silently dropping our custom X-RateLimit-Remaining header for CORS requests. We built our whole client-side throttling around that header, and it worked in staging for 3 weeks. Went to production on a Tuesday and our partner integration started hammering us with 429s because their code read the header as null and assumed infinite quota. The stat that got me was that 38% of our traffic was affected before we caught it. Anyone else trust vendor gateway headers without verifying them first?
1 comments

Log in to join the discussion

Log In
1 Comment
evanc92
evanc9223d ago
Whoa okay, hold on. Tbh I think you might be overthinking this one just a little bit. Every gateway has quirks like this, 38% sounds bad but it's not like your whole system went down. You caught it, you fixed it, that's basically the job. I've seen way worse where the vendor just straight up lies in their docs and you don't even have a custom header to blame. Just add a fallback check in your client code and move on, it's not worth losing sleep over.
1