Class RateLimitKeys

java.lang.Object
com.codename1.backend.security.ratelimit.RateLimitKeys

public final class RateLimitKeys extends Object
The keys a request is usually counted under.
  • Method Details

    • clientAddress

      public static RateLimitKeyResolver clientAddress()

      The address of the client: HttpServer.Request.getRemoteAddress(). The one key a request has before anybody has signed in, and so the one for a login form.

      Behind a load balancer this is the load balancer's address -- one key for every client there is -- until the server is told to believe the forwarding headers: cn1.server.forwardHeaders.

    • clientNetwork

      public static RateLimitKeyResolver clientNetwork()

      The client's network: its address, with an IPv6 address cut to its first 64 bits. The key for a bound on guesses.

      One IPv6 subscriber is handed 2^64 addresses or more, so a count kept for each address is a count the client resets by picking another. The first four groups are the part its provider assigned. An IPv4 address is the key whole. The address is HttpServer.Request.getRemoteAddress(), with everything clientAddress() says about a proxy.

    • principal

      public static RateLimitKeyResolver principal()
      The name of who is signed in; no key for a request nobody signed in for.
    • sessionId

      public static RateLimitKeyResolver sessionId()
      The id of the request's session; no key for a request without one.
    • apiKeyId

      public static RateLimitKeyResolver apiKeyId()
      The id of the API key the request presented; no key for a request that signed in another way.
    • firstOf

      public static RateLimitKeyResolver firstOf(RateLimitKeyResolver... resolvers)
      The first of resolvers that has a key for the request: who is signed in, or else the client's address.