diff --git a/app/config.py b/app/config.py index 09addb15..70c50ae5 100644 --- a/app/config.py +++ b/app/config.py @@ -1133,43 +1133,18 @@ class Settings(BaseSettings): ), ) - # Database Connection Pool Configuration - # Controls SQLAlchemy QueuePool behaviour for PostgreSQL/MySQL. - # SQLite uses NullPool and ignores these settings. - db_pool_size: int = Field( - default=5, - description="Number of persistent connections kept in the pool. Ignored for SQLite.", - ) - db_max_overflow: int = Field( - default=10, - description=("Maximum number of connections that can be opened beyond db_pool_size. Ignored for SQLite."), - ) - db_pool_timeout: int = Field( - default=30, - description="Seconds to wait for a connection from the pool before raising an error. Ignored for SQLite.", - ) - db_pool_recycle: int = Field( - default=1800, - description=( - "Seconds after which a connection is recycled to prevent stale connections. " - "Ignored for SQLite. Default: 1800 (30 minutes)." - ), - ) - - # Per-user upload rate limiting (health-aware limiter) - # Controls how many uploads a single user may submit within a sliding window. + # Per-user upload rate limiting (health-aware, Redis-backed sliding window) upload_rate_limit_per_user: int = Field( default=20, description=( - "Maximum number of uploads allowed per user within the upload_rate_limit_window. " - "The limiter may dynamically reduce this value when Redis queue depth or CPU load is high." + "Maximum number of file uploads allowed per user within the sliding window. " + "The effective limit may be reduced dynamically when the system is under heavy load " + "(high queue depth or CPU usage). Set to 0 to disable per-user upload rate limiting." ), ) upload_rate_limit_window: int = Field( default=60, - description=( - "Sliding window in seconds over which upload_rate_limit_per_user is enforced. Default: 60 seconds." - ), + description="Sliding window size in seconds for per-user upload rate limiting (default: 60).", ) # Rate Limiting Configuration (see SECURITY_AUDIT.md and docs/API.md) @@ -1191,20 +1166,6 @@ class Settings(BaseSettings): description="Stricter rate limit for authentication endpoints to prevent brute force attacks.", ) - # Per-user upload rate limiting (health-aware, Redis-backed sliding window) - upload_rate_limit_per_user: int = Field( - default=20, - description=( - "Maximum number of file uploads allowed per user within the sliding window. " - "The effective limit may be reduced dynamically when the system is under heavy load " - "(high queue depth or CPU usage). Set to 0 to disable per-user upload rate limiting." - ), - ) - upload_rate_limit_window: int = Field( - default=60, - description="Sliding window size in seconds for per-user upload rate limiting (default: 60).", - ) - # CORS Configuration (see SECURITY_AUDIT.md – Infrastructure Security section) # Disabled by default since most deployments use a reverse proxy (Traefik, Nginx, etc.) # that already adds CORS headers. Enable only if deploying without a reverse proxy or if diff --git a/app/utils/settings_service.py b/app/utils/settings_service.py index 6a912bfc..41fe3874 100644 --- a/app/utils/settings_service.py +++ b/app/utils/settings_service.py @@ -2601,51 +2601,6 @@ SETTING_METADATA = { "required": False, "restart_required": False, }, - # Database Connection Pool - "db_pool_size": { - "category": "Core", - "description": ( - "Number of persistent connections kept in the SQLAlchemy QueuePool. " - "Has no effect for SQLite databases. Default: 5." - ), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": True, - }, - "db_max_overflow": { - "category": "Core", - "description": ( - "Maximum extra connections that can be opened beyond db_pool_size. " - "Has no effect for SQLite databases. Default: 10." - ), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": True, - }, - "db_pool_timeout": { - "category": "Core", - "description": ( - "Seconds to wait for a connection from the pool before raising an error. " - "Has no effect for SQLite databases. Default: 30." - ), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": True, - }, - "db_pool_recycle": { - "category": "Core", - "description": ( - "Seconds after which idle connections are recycled to prevent stale connections. " - "Has no effect for SQLite databases. Default: 1800 (30 minutes)." - ), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": True, - }, # Per-user upload rate limiting "upload_rate_limit_per_user": { "category": "Security", @@ -2704,26 +2659,6 @@ SETTING_METADATA = { "required": False, "restart_required": True, }, - "upload_rate_limit_per_user": { - "category": "Security", - "description": ( - "Maximum number of file uploads allowed per user within the sliding window. " - "The effective limit may be reduced dynamically when the system is under heavy load. " - "Set to 0 to disable per-user upload rate limiting. Default: 20." - ), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": False, - }, - "upload_rate_limit_window": { - "category": "Security", - "description": ("Sliding window size in seconds for per-user upload rate limiting. Default: 60."), - "type": "integer", - "sensitive": False, - "required": False, - "restart_required": False, - }, # CORS "cors_enabled": { "category": "Security",