v12.3.7
datalab-to/suryav12.3.7Apr 20, 2026by thedotmack
AI Summary
Refactor to remove bearer auth and platform_source context filter, replacing with a simple in-memory rate limiter as a lightweight compensating control.
Key Highlights
- Drop bearer-token auth from worker API
- Drop platform_source query-time filter
- In-memory rate limiter (300 req/min) as compensating control
- Rate limiter normalises IPv4-mapped IPv6
- Deleted auth-token.ts and all dependents
New Features
- Removed Authorization header from worker-utils.ts
- Removed token injection from ViewerRoutes.ts
- In-memory rate limiter with Retry-After on 429
- Size-guarded prune for rate limiter
Full Release Notes
## What's Changed **Refactor: remove bearer auth and platform_source context filter** (#2081) - Drop bearer-token auth from the worker API. Worker binds localhost-only and CORS restricts origins to localhost — the token added friction for every internal client (hooks, CLI, viewer, sync script) with no real security benefit for single-user local deployments. - Drop the unused `platform_source` query-time filter from the `/api/context/inject` pipeline (ContextBuilder, ObservationCompiler, SearchRoutes, context handler, transcripts processor). The DB column stays — only the WHERE-clause filter and its plumbing are removed. - Replace the removed auth with a simple in-memory rate limiter (300 req/min) as a lightweight compensating control. Limiter normalises IPv4-mapped IPv6, emits `Retry-After` on 429, and has a size-guarded prune that never runs on localhost. ## Cleanup - Deleted `src/shared/auth-token.ts` and all its dependents (`worker-utils.ts` Authorization header, `ViewerRoutes.ts` token injection, CORS `allowedHeaders: ['Authorization']`, `sync-marketplace.cjs` admin restart header). - Stopped tracking `.docker-blowout-data/claude-mem.db` and added the directory to `.gitignore`. ## Full Changelog https://github.com/thedotmack/claude-mem/compare/v12.3.6...v12.3.7