Skip to content

docs: document REQUIRE_AUTHORIZATION_CONSENT and rate limit env vars - #51

Merged
ml-aixolotl merged 3 commits into
mainfrom
copilot/update-readme-and-env-example
Jul 3, 2026
Merged

ml-aixolotl merged 3 commits into
mainfrom
copilot/update-readme-and-env-example

Conversation

Copilot AI commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

REQUIRE_AUTHORIZATION_CONSENT, RATE_LIMIT_MAX_REQUESTS, and RATE_LIMIT_WINDOW_MINUTES were undocumented — present in config but without guidance on purpose, defaults, or when to change them.

.env.example

  • REQUIRE_AUTHORIZATION_CONSENT: expanded to explain the confused-deputy attack prevention, production vs. local-dev tradeoff, and link to FastMCP docs
  • RATE_LIMIT_MAX_REQUESTS / RATE_LIMIT_WINDOW_MINUTES: added as commented-out entries with defaults (120 req / 1 min) so operators know the knobs exist without activating them

README.md

  • Configuration section .env block mirrors the same expanded comments
  • Added prose notes after the block calling out when to change REQUIRE_AUTHORIZATION_CONSENT (false only in local dev) and that the rate limit vars are optional overrides
  • Docker run section references both rate limit vars for operators configuring via -e

@ml-aixolotl
ml-aixolotl marked this pull request as ready for review July 3, 2026 08:24
Copilot AI review requested due to automatic review settings July 3, 2026 08:24
@ml-aixolotl
ml-aixolotl merged commit 3e51ecb into main Jul 3, 2026
1 check passed
@ml-aixolotl
ml-aixolotl deleted the copilot/update-readme-and-env-example branch July 3, 2026 08:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documents previously-implicit environment variables that control FastMCP’s OAuth consent behavior and the server’s per-client sliding-window rate limiting, so operators understand purpose, defaults, and when to override.

Changes:

  • Expanded documentation for REQUIRE_AUTHORIZATION_CONSENT (purpose, default, and local-dev guidance) in both .env.example and the README config section.
  • Added commented-out RATE_LIMIT_MAX_REQUESTS / RATE_LIMIT_WINDOW_MINUTES entries (with defaults) to make the available knobs discoverable without changing behavior.
  • Updated the Docker run instructions to mention how to override the rate limit settings via -e.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
README.md Expands .env documentation for consent + rate limiting and references rate limit overrides in the Docker run section.
.env.example Adds explanatory comments and commented-out entries for consent and rate-limit env vars, including defaults and a FastMCP docs link.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants