Skip to main content

Module ratelimit

Module ratelimit 

Source
Expand description

Verification-request limits keyed by source and destination.

Separate token buckets protect the caller-IP and target-address axes. Their state is process-local, bounded in size, and reset when the service restarts.

ConstantsΒ§

RATELIMIT_MAP_CAP πŸ”’
Cap on each bucket table; fully refilled buckets are pruned past it so a spray cannot grow the table without bound.
RC_BURST πŸ”’
RC_PER_SECOND πŸ”’
Refills per second on each requestToken bucket; a generous burst absorbs a real client’s retries while bounding sustained spray.

FunctionsΒ§

check_bucket πŸ”’
check_bucket_at πŸ”’
debit_bucket πŸ”’