mirror of
https://github.com/whit3rabbit/anyllm-proxy.git
synced 2026-10-03 00:00:07 +00:00
Defense-in-depth against token brute-force on the admin API. Uses a DashMap-based sliding window (60s) per client IP, applied as the outermost middleware layer on protected admin routes. Admin server now uses into_make_service_with_connect_info to expose client IP. Limit is configurable at runtime via set_admin_rpm for test flexibility. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>