Package com.codename1.backend.security.ratelimit
package com.codename1.backend.security.ratelimit
Limits on how often a client may ask: a
RateLimiter counts requests under
a key, and a
RateLimitKeyResolver says which
key a request counts under -- its client's address, who it is signed in as,
its session, its API key.
http.rateLimit("/login", RateLimitKeys.clientAddress(), new InMemoryRateLimiter(5, 60));
A request over its limit is answered 429 with Retry-After, before it
reaches anything that costs: a password hash, a query.
-
ClassDescriptionA limit kept in this process's memory: a token bucket per key.Counts in the server's database, in the
cn1_rate_limittable ofSecuritySchema, so that every process of a deployment shares one limit.Counts requests under a key and says when there have been too many.Says which key a request counts under.The keys a request is usually counted under.