Table of Contents

RateLimiter

Layer: Core · Source: lib/core/RateLimiter.php:21 (lines 21–219)


class RateLimiter

RateLimiter

File-based sliding window rate limiter for API endpoints. Uses IP address as the default key. Stores request timestamps in per-key files under the cache directory.

Compatible with PHP 7.4+.

Docblock Metadata

Tag Value
@category Core Class
@author Blogware Team
@license MIT
@version 1.0

Inheritance

No parent, interface or trait. This is a root type.

Constants (2)

Visibility Name Value Line
- DEFAULT_LIMIT 60; 26
- DEFAULT_WINDOW 60; 31

Properties (1)

Visibility Type Name Default Line
private (untyped) $cacheDir 38

Methods (8)

Visibility Method Summary Line
public __construct() Constructor 45
private ensureCacheDir() Ensure the cache directory exists and is writable 56
public check() Check if the current request exceeds the rate limit 72
private readTimestamps() Read timestamps from file, filtering out expired ones 119
private writeTimestamps() Write timestamps to file 148
private getClientKey() Generate a unique key for the current client 167
public reset() Reset rate limit for a specific key 178
public cleanup() Clean up expired rate limit files 196

__construct()

public function __construct($cacheDir = null)

lines 45–49 (5)

Constructor

Parameter Type Default Description
$cacheDir (untyped) null Override cache directory path

ensureCacheDir()

private function ensureCacheDir()

lines 56–61 (6)

Ensure the cache directory exists and is writable

Takes no parameters.

Returns: (none declared) — void

check()

public function check($key = null, $limit = self::DEFAULT_LIMIT, $window = self::DEFAULT_WINDOW, $namespace = '')

lines 72–110 (39)

Check if the current request exceeds the rate limit

Parameter Type Default Description
$key (untyped) null Unique identifier (default: client IP)
$limit (untyped) self::DEFAULT_LIMIT Maximum requests allowed in the window
$window (untyped) self::DEFAULT_WINDOW Window size in seconds
$namespace (untyped) '''''' Optional counter namespace (e.g. 'read' vs 'write')

Returns: (none declared) — array Result with limit, remaining, reset, retry_after, allowed

readTimestamps()

private function readTimestamps($file, $windowStart)

lines 119–138 (20)

Read timestamps from file, filtering out expired ones

Parameter Type Default Description
$file (untyped) required File path
$windowStart (untyped) required Earliest valid timestamp

Returns: (none declared) — array Valid timestamps

writeTimestamps()

private function writeTimestamps($file, $timestamps, $windowStart)

lines 148–155 (8)

Write timestamps to file

Parameter Type Default Description
$file (untyped) required File path
$timestamps (untyped) required Timestamps to write
$windowStart (untyped) required Earliest valid timestamp

Returns: (none declared) — void

getClientKey()

private function getClientKey()

lines 167–170 (4)

Generate a unique key for the current client

Always keys on the client IP address. Previously the bucket key was derived from the attacker-controlled X-API-Key header when present, which let a client pick a fresh bucket per request and bypass the rate limit entirely.

Takes no parameters.

Returns: (none declared) — string

reset()

public function reset($key = null)

lines 178–188 (11)

Reset rate limit for a specific key

Parameter Type Default Description
$key (untyped) null Unique identifier

Returns: (none declared) — bool

cleanup()

public function cleanup($maxAge = 3600)

lines 196–218 (23)

Clean up expired rate limit files

Parameter Type Default Description
$maxAge (untyped) 3600 Maximum age in seconds before file is considered stale

Returns: (none declared) — int Number of files cleaned


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.