====== RateLimiter ====== **Layer:** ''Core'' · **Source:** ''lib/core/RateLimiter.php:21'' (lines 21–219) ---- class RateLimiter RateLimiter File-based sliding window rate limiter for API endpoints. Uses IP address as the default key. Stores request timestamps in per-key files under the cache directory. Compatible with PHP 7.4+. ======= Docblock Metadata ======= ^ Tag ^ Value ^ | ''@category'' | Core Class | | ''@author'' | Blogware Team | | ''@license'' | MIT | | ''@version'' | 1.0 | ======= Inheritance ======= //No parent, interface or trait. This is a root type.// ======= Constants (2) ======= ^ Visibility ^ Name ^ Value ^ Line ^ | ''-'' | ''DEFAULT_LIMIT'' | ''60;'' | 26 | | ''-'' | ''DEFAULT_WINDOW'' | ''60;'' | 31 | ======= Properties (1) ======= ^ Visibility ^ Type ^ Name ^ Default ^ Line ^ | ''private'' | ''(untyped)'' | ''$cacheDir'' | | 38 | ======= Methods (8) ======= ^ Visibility ^ Method ^ Summary ^ Line ^ | public | ''__construct()'' | Constructor | 45 | | private | ''ensureCacheDir()'' | Ensure the cache directory exists and is writable | 56 | | public | ''check()'' | Check if the current request exceeds the rate limit | 72 | | private | ''readTimestamps()'' | Read timestamps from file, filtering out expired ones | 119 | | private | ''writeTimestamps()'' | Write timestamps to file | 148 | | private | ''getClientKey()'' | Generate a unique key for the current client | 167 | | public | ''reset()'' | Reset rate limit for a specific key | 178 | | public | ''cleanup()'' | Clean up expired rate limit files | 196 | ======== __construct() ======== public function __construct($cacheDir = null) //lines 45–49 (5)// Constructor ^ Parameter ^ Type ^ Default ^ Description ^ | ''$cacheDir'' | ''(untyped)'' | ''null'' | Override cache directory path | ======== ensureCacheDir() ======== private function ensureCacheDir() //lines 56–61 (6)// Ensure the cache directory exists and is writable //Takes no parameters.// **Returns:** ''(none declared)'' — void ======== check() ======== public function check($key = null, $limit = self::DEFAULT_LIMIT, $window = self::DEFAULT_WINDOW, $namespace = '') //lines 72–110 (39)// Check if the current request exceeds the rate limit ^ Parameter ^ Type ^ Default ^ Description ^ | ''$key'' | ''(untyped)'' | ''null'' | Unique identifier (default: client IP) | | ''$limit'' | ''(untyped)'' | ''self::DEFAULT_LIMIT'' | Maximum requests allowed in the window | | ''$window'' | ''(untyped)'' | ''self::DEFAULT_WINDOW'' | Window size in seconds | | ''$namespace'' | ''(untyped)'' | '''''' | Optional counter namespace (e.g. 'read' vs 'write') | **Returns:** ''(none declared)'' — array Result with limit, remaining, reset, retry_after, allowed ======== readTimestamps() ======== private function readTimestamps($file, $windowStart) //lines 119–138 (20)// Read timestamps from file, filtering out expired ones ^ Parameter ^ Type ^ Default ^ Description ^ | ''$file'' | ''(untyped)'' | //required// | File path | | ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp | **Returns:** ''(none declared)'' — array Valid timestamps ======== writeTimestamps() ======== private function writeTimestamps($file, $timestamps, $windowStart) //lines 148–155 (8)// Write timestamps to file ^ Parameter ^ Type ^ Default ^ Description ^ | ''$file'' | ''(untyped)'' | //required// | File path | | ''$timestamps'' | ''(untyped)'' | //required// | Timestamps to write | | ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp | **Returns:** ''(none declared)'' — void ======== getClientKey() ======== private function getClientKey() //lines 167–170 (4)// Generate a unique key for the current client Always keys on the client IP address. Previously the bucket key was derived from the attacker-controlled X-API-Key header when present, which let a client pick a fresh bucket per request and bypass the rate limit entirely. //Takes no parameters.// **Returns:** ''(none declared)'' — string ======== reset() ======== public function reset($key = null) //lines 178–188 (11)// Reset rate limit for a specific key ^ Parameter ^ Type ^ Default ^ Description ^ | ''$key'' | ''(untyped)'' | ''null'' | Unique identifier | **Returns:** ''(none declared)'' — bool ======== cleanup() ======== public function cleanup($maxAge = 3600) //lines 196–218 (23)// Clean up expired rate limit files ^ Parameter ^ Type ^ Default ^ Description ^ | ''$maxAge'' | ''(untyped)'' | ''3600'' | Maximum age in seconds before file is considered stale | **Returns:** ''(none declared)'' — int Number of files cleaned ---- //This page is generated from source by 'tools/gendoc'. Edits will be overwritten.//