Skip to main content

Overview

The rollback endpoint allows administrators to close all pull requests created during a burst attack window. This feature is designed to clean up spam PRs created by bots or coordinated abuse campaigns.
This endpoint is protected by admin authentication and strict rate limiting (5 requests/minute).

Endpoint

Authentication

The endpoint accepts two forms of authentication:
  1. Static password - The PANIC_PASSWORD environment variable configured during deployment
  2. Single-use action token - Time-limited tokens (10 minutes TTL) generated for ntfy alert action buttons

Request Body

string
Admin password for rollback control. Must match the PANIC_PASSWORD environment variable.
string
Single-use action token generated by the system. Expires after 10 minutes.
You must provide either password or token, but not both.

Response

integer
Number of PRs successfully closed.
integer
Number of PRs that failed to close.
array
Array of PR URLs that were successfully closed.
array
Array of PR URLs that failed to close (with error details logged server-side).

Behavior

2-Hour Window

The rollback mechanism tracks PRs created during burst activity. PRs are registered for rollback only when:
  1. A global burst alert is active (triggered when suspicious activity is detected)
  2. The PR is less than 2 hours old (older entries are automatically pruned)
This ensures rollback only affects recent burst activity, not legitimate PRs.

Concurrent Processing

PRs are closed in parallel using up to 5 concurrent workers to minimize API rate limits and processing time.

Rate Limiting

The rollback endpoint has its own rate limit:
  • 5 requests per minute (regardless of IP)
  • Exceeding this limit returns 429 Too Many Requests

Examples

How PRs Are Tracked

From handlers.go:332-349, PRs are registered during push operations:

Implementation Details

From handlers.go:826-909:

When to Use Rollback

Use the rollback endpoint when:
  • You’ve received a burst alert notification from ntfy
  • You’ve identified a pattern of spam PRs in the recent activity logs
  • You’ve activated panic mode and want to clean up the damage
  • You need to close multiple abusive PRs quickly without manual GitHub UI interaction
Rollback only affects PRs created during the active burst window (up to 2 hours). Legitimate PRs created before the attack are unaffected.