Retry After What? — JavaScript Bug Hunt
Inspired by the API clients that hammer rate-limited services into the ground.
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: HTTP, Parsing
- Modelled on: Slack API clients
- Visible tests: numeric seconds become milliseconds; http dates wait until the date; missing header falls back to one second
- Reward: 50 XP for a complete fix
Briefing
Inspired by the API clients that hammer rate-limited services into the ground. The Retry-After header legally comes in TWO shapes — a number of seconds, or an HTTP date — and this client handles neither correctly.
Fix backoff.js before the vendor blocks the whole IP range.
Bug report
BUG-429 · Priority: High · Reported by: integrations
retryDelayMs(retryAfter, nowMs):
- numeric string ("30") -> that many SECONDS, as milliseconds
- HTTP date string -> delay until that date (clamped to >= 0)
- missing/unparseable -> default 1000ms
Observed: "30" is treated as 30 MILLISECONDS, and date headers become NaN, so the client retries instantly, forever.
Logs
[client] 429 retry-after="30" -> sleeping 30ms
[client] 429 retry-after="Wed, 21 Oct 2026 07:28:00 GMT" -> sleeping NaNThe code as shipped
src/http/backoff.js (editable)
// Turns a Retry-After header into a delay in milliseconds.
exports.retryDelayMs = function (retryAfter, nowMs) {
return parseInt(retryAfter, 10);
};
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.