Retry After What? — JavaScript Bug Hunt

Inspired by the API clients that hammer rate-limited services into the ground.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: HTTP, Parsing
  • Modelled on: Slack API clients
  • Visible tests: numeric seconds become milliseconds; http dates wait until the date; missing header falls back to one second
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the API clients that hammer rate-limited services into the ground. The Retry-After header legally comes in TWO shapes — a number of seconds, or an HTTP date — and this client handles neither correctly.

Fix backoff.js before the vendor blocks the whole IP range.

Bug report

BUG-429 · Priority: High · Reported by: integrations

retryDelayMs(retryAfter, nowMs):

  • numeric string ("30") -> that many SECONDS, as milliseconds
  • HTTP date string -> delay until that date (clamped to >= 0)
  • missing/unparseable -> default 1000ms

Observed: "30" is treated as 30 MILLISECONDS, and date headers become NaN, so the client retries instantly, forever.

Logs

[client] 429 retry-after="30" -> sleeping 30ms
[client] 429 retry-after="Wed, 21 Oct 2026 07:28:00 GMT" -> sleeping NaN

The code as shipped

src/http/backoff.js (editable)

// Turns a Retry-After header into a delay in milliseconds.
exports.retryDelayMs = function (retryAfter, nowMs) {
  return parseInt(retryAfter, 10);
};

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.