Class RateLimitKeys
-
Method Summary
Modifier and TypeMethodDescriptionstatic RateLimitKeyResolverapiKeyId()The id of the API key the request presented; no key for a request that signed in another way.static RateLimitKeyResolverThe address of the client:HttpServer.Request.getRemoteAddress().static RateLimitKeyResolverThe client's network: its address, with an IPv6 address cut to its first 64 bits.static RateLimitKeyResolverfirstOf(RateLimitKeyResolver... resolvers) The first ofresolversthat has a key for the request: who is signed in, or else the client's address.static RateLimitKeyResolverThe name of who is signed in; no key for a request nobody signed in for.static RateLimitKeyResolverThe id of the request's session; no key for a request without one.
-
Method Details
-
clientAddress
The address of the client:
HttpServer.Request.getRemoteAddress(). The one key a request has before anybody has signed in, and so the one for a login form.Behind a load balancer this is the load balancer's address -- one key for every client there is -- until the server is told to believe the forwarding headers:
cn1.server.forwardHeaders. -
clientNetwork
The client's network: its address, with an IPv6 address cut to its first 64 bits. The key for a bound on guesses.
One IPv6 subscriber is handed 2^64 addresses or more, so a count kept for each address is a count the client resets by picking another. The first four groups are the part its provider assigned. An IPv4 address is the key whole. The address is
HttpServer.Request.getRemoteAddress(), with everythingclientAddress()says about a proxy. -
principal
The name of who is signed in; no key for a request nobody signed in for. -
sessionId
The id of the request's session; no key for a request without one. -
apiKeyId
The id of the API key the request presented; no key for a request that signed in another way. -
firstOf
The first ofresolversthat has a key for the request: who is signed in, or else the client's address.
-