+13
−5
Loading
cooldownLimiter began as the wake-only throttle; the OTP-start hardening reused it via the atomic reserve/release. Its type comment still called it a per-server wake limiter and justified the per-replica behaviour as "acceptable because the operator reconcile is idempotent" -- true for wake, false for OTP, whose every admitted send is a non-idempotent email. Rewrite the comment to describe the shared per-key limiter and record the honest KNOWN-LIMITATION: the atomic reserve/release closes the intra-replica concurrent burst, but the in-memory map throttles per replica, so cross-replica bounding still needs a shared store. No behaviour change.