Rate limit getAgentFlow permission failures

What does this MR do and why?

Resolves gitlab-com/gl-infra/production-engineering#29119 (closed)

Polling from old open tabs can cause continious auth errors in the getAgentFlow graphQL endpoint. This can be problematic for monitoring purposes. This commit adds a rate limiter in front of that.

Changelog: added EE: true

References

gitlab-com/gl-infra/production-engineering#29119 (closed)

Screenshots or screen recordings

Screenshot_2026-07-15_at_15.17.26

How to set up and validate locally

  1. In order to reproduce an permission error easily, change a editor session's user
session = ::Ai::DuoWorkflows::Workflow.where.not(environment: 'web')
session.update(user: User.find(2))
session.id
  1. Visit the session page
  2. http://gdk.test:3000/namespace/project/-/automate/agent-sessions/id-from-above
  3. Refresh the page
  4. You should see too many requests error

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Halil Coban

Merge request reports

Loading
Loading