Repository navigation
docs: document REQUIRE_AUTHORIZATION_CONSENT and rate limit env vars - #51
Merged
Merged
Conversation
Copilot created this pull request from a session on behalf of
ml-aixolotl
July 3, 2026 08:18
View session
ml-aixolotl
approved these changes
Jul 3, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
Documents previously-implicit environment variables that control FastMCP’s OAuth consent behavior and the server’s per-client sliding-window rate limiting, so operators understand purpose, defaults, and when to override.
Changes:
- Expanded documentation for
REQUIRE_AUTHORIZATION_CONSENT(purpose, default, and local-dev guidance) in both.env.exampleand the README config section. - Added commented-out
RATE_LIMIT_MAX_REQUESTS/RATE_LIMIT_WINDOW_MINUTESentries (with defaults) to make the available knobs discoverable without changing behavior. - Updated the Docker run instructions to mention how to override the rate limit settings via
-e.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| README.md | Expands .env documentation for consent + rate limiting and references rate limit overrides in the Docker run section. |
| .env.example | Adds explanatory comments and commented-out entries for consent and rate-limit env vars, including defaults and a FastMCP docs link. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
REQUIRE_AUTHORIZATION_CONSENT,RATE_LIMIT_MAX_REQUESTS, andRATE_LIMIT_WINDOW_MINUTESwere undocumented — present in config but without guidance on purpose, defaults, or when to change them..env.exampleREQUIRE_AUTHORIZATION_CONSENT: expanded to explain the confused-deputy attack prevention, production vs. local-dev tradeoff, and link to FastMCP docsRATE_LIMIT_MAX_REQUESTS/RATE_LIMIT_WINDOW_MINUTES: added as commented-out entries with defaults (120req /1min) so operators know the knobs exist without activating themREADME.md.envblock mirrors the same expanded commentsREQUIRE_AUTHORIZATION_CONSENT(falseonly in local dev) and that the rate limit vars are optional overrides-e