gabriel / musehub public
fix BREAKING fix/install-script-bot-throttle #1 / 1
gabriel · 172 days ago · Apr 9, 2026 · Diff

fix: exempt /install.sh and /uninstall.sh from bot throttle

curl -fsSL staging.musehub.ai/install.sh | sh was returning 429 because the default curl UA matches the bot-throttle block list. The install script is specifically designed to be fetched by curl before muse is installed, so /install.sh and /uninstall.sh are now unconditionally exempt from UA-based blocking — same as /healthz and /static/.

sha256:2c483a3d40b5b66f11e1ee41f2d1816dbcc535fb32257ccaca2f79f105138014 sha
+3 ~1 symbols
sha256:e649056b503bdac2ea2e9851365823cf3d2a8f4d2f9e98c0ded80573285b7e18 snapshot
+3
symbols added
~1
symbol modified
0
dead code introduced
Semantic Changes 4 symbols
~ tests/test_bot_throttle.py .py 3 symbols added
+ test_install_script_passes_with_curl_ua function async_function test_install_script_passes_with_curl_ua L198–205
+ test_install_script_passes_with_no_ua function async_function test_install_script_passes_with_no_ua L216–219
+ test_uninstall_script_passes_with_curl_ua function async_function test_uninstall_script_passes_with_curl_ua L209–212
← Older Oldest on fix/install-script-bot-throttle
All commits
Newer → Latest on fix/install-script-bot-throttle

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:2c483a3d40b5b66f11e1ee41f2d1816dbcc535fb32257ccaca2f79f105138014 --body "your comment"