====== RateLimiter ======
**Layer:** ''Core'' · **Source:** ''lib/core/RateLimiter.php:21'' (lines 21–219)
----
class RateLimiter
RateLimiter
File-based sliding window rate limiter for API endpoints.
Uses IP address as the default key. Stores request timestamps
in per-key files under the cache directory.
Compatible with PHP 7.4+.
======= Docblock Metadata =======
^ Tag ^ Value ^
| ''@category'' | Core Class |
| ''@author'' | Blogware Team |
| ''@license'' | MIT |
| ''@version'' | 1.0 |
======= Inheritance =======
//No parent, interface or trait. This is a root type.//
======= Constants (2) =======
^ Visibility ^ Name ^ Value ^ Line ^
| ''-'' | ''DEFAULT_LIMIT'' | ''60;'' | 26 |
| ''-'' | ''DEFAULT_WINDOW'' | ''60;'' | 31 |
======= Properties (1) =======
^ Visibility ^ Type ^ Name ^ Default ^ Line ^
| ''private'' | ''(untyped)'' | ''$cacheDir'' | | 38 |
======= Methods (8) =======
^ Visibility ^ Method ^ Summary ^ Line ^
| public | ''__construct()'' | Constructor | 45 |
| private | ''ensureCacheDir()'' | Ensure the cache directory exists and is writable | 56 |
| public | ''check()'' | Check if the current request exceeds the rate limit | 72 |
| private | ''readTimestamps()'' | Read timestamps from file, filtering out expired ones | 119 |
| private | ''writeTimestamps()'' | Write timestamps to file | 148 |
| private | ''getClientKey()'' | Generate a unique key for the current client | 167 |
| public | ''reset()'' | Reset rate limit for a specific key | 178 |
| public | ''cleanup()'' | Clean up expired rate limit files | 196 |
======== __construct() ========
public function __construct($cacheDir = null)
//lines 45–49 (5)//
Constructor
^ Parameter ^ Type ^ Default ^ Description ^
| ''$cacheDir'' | ''(untyped)'' | ''null'' | Override cache directory path |
======== ensureCacheDir() ========
private function ensureCacheDir()
//lines 56–61 (6)//
Ensure the cache directory exists and is writable
//Takes no parameters.//
**Returns:** ''(none declared)'' — void
======== check() ========
public function check($key = null, $limit = self::DEFAULT_LIMIT, $window = self::DEFAULT_WINDOW, $namespace = '')
//lines 72–110 (39)//
Check if the current request exceeds the rate limit
^ Parameter ^ Type ^ Default ^ Description ^
| ''$key'' | ''(untyped)'' | ''null'' | Unique identifier (default: client IP) |
| ''$limit'' | ''(untyped)'' | ''self::DEFAULT_LIMIT'' | Maximum requests allowed in the window |
| ''$window'' | ''(untyped)'' | ''self::DEFAULT_WINDOW'' | Window size in seconds |
| ''$namespace'' | ''(untyped)'' | '''''' | Optional counter namespace (e.g. 'read' vs 'write') |
**Returns:** ''(none declared)'' — array Result with limit, remaining, reset, retry_after, allowed
======== readTimestamps() ========
private function readTimestamps($file, $windowStart)
//lines 119–138 (20)//
Read timestamps from file, filtering out expired ones
^ Parameter ^ Type ^ Default ^ Description ^
| ''$file'' | ''(untyped)'' | //required// | File path |
| ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |
**Returns:** ''(none declared)'' — array Valid timestamps
======== writeTimestamps() ========
private function writeTimestamps($file, $timestamps, $windowStart)
//lines 148–155 (8)//
Write timestamps to file
^ Parameter ^ Type ^ Default ^ Description ^
| ''$file'' | ''(untyped)'' | //required// | File path |
| ''$timestamps'' | ''(untyped)'' | //required// | Timestamps to write |
| ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |
**Returns:** ''(none declared)'' — void
======== getClientKey() ========
private function getClientKey()
//lines 167–170 (4)//
Generate a unique key for the current client
Always keys on the client IP address. Previously the bucket key was
derived from the attacker-controlled X-API-Key header when present,
which let a client pick a fresh bucket per request and bypass the
rate limit entirely.
//Takes no parameters.//
**Returns:** ''(none declared)'' — string
======== reset() ========
public function reset($key = null)
//lines 178–188 (11)//
Reset rate limit for a specific key
^ Parameter ^ Type ^ Default ^ Description ^
| ''$key'' | ''(untyped)'' | ''null'' | Unique identifier |
**Returns:** ''(none declared)'' — bool
======== cleanup() ========
public function cleanup($maxAge = 3600)
//lines 196–218 (23)//
Clean up expired rate limit files
^ Parameter ^ Type ^ Default ^ Description ^
| ''$maxAge'' | ''(untyped)'' | ''3600'' | Maximum age in seconds before file is considered stale |
**Returns:** ''(none declared)'' — int Number of files cleaned
----
//This page is generated from source by 'tools/gendoc'. Edits will be overwritten.//