Class JdbcRateLimiter
java.lang.Object
com.codename1.backend.security.ratelimit.JdbcRateLimiter
- All Implemented Interfaces:
RateLimiter
Counts in the server's database, in the cn1_rate_limit table of
SecuritySchema, so that every process of a
deployment shares one limit.
http.rateLimit("/login", RateLimitKeys.clientAddress(),
new JdbcRateLimiter(dataSource, "login", 5, 60));
A fixed window: permits requests in each periodSeconds, counted from the
first request of the window. Every request is decided by one conditional
UPDATE and the number of rows it changed, so two processes counting at
the same moment cannot both take the last permit.
It costs a statement or two per request it counts, which is the price of
agreeing across processes; InMemoryRateLimiter costs none and counts for
its own process alone. A database that cannot be reached refuses nobody:
the limit is a courtesy to the server, and a store that is down must not
take the application with it.
-
Constructor Summary
ConstructorsConstructorDescriptionJdbcRateLimiter(DataSource dataSource, String name, int permits, long periodSeconds) -
Method Summary
Modifier and TypeMethodDescriptionintdeleteExpired(long olderThanSeconds) Deletes the counts of every limiter whose window ended more thanolderThanSecondsago; for a scheduled job, since a key that is never seen again leaves its row behind.A limiter over the same table, undername, read on the same clock.voidDeletes the row ofkey.longretryAfterSeconds(String key) How many seconds a request just refused underkeyshould wait before trying again: what itsRetry-Aftersays.voidbooleantryAcquire(String key) Counts one request underkey.
-
Constructor Details
-
JdbcRateLimiter
- Parameters:
name- what keeps this limiter's counts apart from another's in the same table; two limiters of one name share their counts on purpose
-
-
Method Details
-
derive
A limiter over the same table, undername, read on the same clock.- Specified by:
derivein interfaceRateLimiter- Parameters:
name- what keeps the new limiter's counts apartpermits- how many requests a key may make in a periodperiodSeconds- the length of the period
-
setClock
-
tryAcquire
Description copied from interface:RateLimiterCounts one request underkey.- Specified by:
tryAcquirein interfaceRateLimiter- Returns:
- whether the request is within the limit
-
reset
Deletes the row ofkey. A database that cannot be reached leaves the count as it is, which is the safe way round for a bound on guesses.- Specified by:
resetin interfaceRateLimiter
-
retryAfterSeconds
Description copied from interface:RateLimiterHow many seconds a request just refused underkeyshould wait before trying again: what itsRetry-Aftersays. One second unless the limiter knows better.- Specified by:
retryAfterSecondsin interfaceRateLimiter
-
deleteExpired
Deletes the counts of every limiter whose window ended more thanolderThanSecondsago; for a scheduled job, since a key that is never seen again leaves its row behind.- Returns:
- how many rows were deleted
- Throws:
IOException
-