Skip to content

feat(ai): add per-user daily token budget guard - #877

Merged
MaryammAli merged 1 commit into
BlockDash-Studios:mainfrom
Essther77-git:feat/ai-token-budget-guard
Sep 25, 2026
Merged

MaryammAli merged 1 commit into
BlockDash-Studios:mainfrom
Essther77-git:feat/ai-token-budget-guard

Conversation

@Essther77-git

Copy link
Copy Markdown
Contributor

Adds a per-user daily token budget for AI Mentor endpoints (BE-072).

  • AiTokenBudgetService tracks token usage per (userId, endpoint) against a daily budget, following the same in-process sliding-window pattern already used by NotificationRateLimiter
  • AiTokenBudgetGuard — a NestJS CanActivate guard applied via @UseGuards(AiTokenBudgetGuard) — rejects requests once a user's daily budget is exhausted with 429 TOKEN_BUDGET_EXCEEDED, a Retry-After header, and an ISO resetAt timestamp
  • getUsageSnapshot() exposes per-user/endpoint usage for metrics export

Runs in-process for now; a multi-instance deployment would swap the Map for a shared store (e.g. Redis), matching the note already on NotificationRateLimiter.

Closes #825
Closes #820
Closes #822
Closes #823

Adds AiTokenBudgetService (tracks token usage per (userId, endpoint)
against a daily budget, following the in-process sliding-window pattern
already used by NotificationRateLimiter) and AiTokenBudgetGuard, a NestJS
CanActivate guard applied via @UseGuards(AiTokenBudgetGuard) that rejects
requests once a user's daily budget is exhausted with 429
TOKEN_BUDGET_EXCEEDED, a Retry-After header, and an ISO resetAt timestamp.
getUsageSnapshot() exposes per-user/endpoint usage for metrics export.
@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@Essther77-git Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@NteinPrecious

Copy link
Copy Markdown
Contributor

Closing — this PR targeted the wrong backend directory (app/backend instead of BackendAcademy, where this feature area actually lives). Reopening against the correct location.

@MaryammAli MaryammAli left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@MaryammAli
MaryammAli merged commit 49b6ae9 into BlockDash-Studios:main Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants