Scriptlog Docs

Scriptlog Documentation

Code reference for the Scriptlog codebase

User Tools

Site Tools


scriptlog:lib:core:ratelimiter

This is an old revision of the document!


RateLimiter

Layer: Core · Source: lib/core/RateLimiter.php:21 (lines 21–219)


class RateLimiter

RateLimiter

File-based sliding window rate limiter for API endpoints. Uses IP address as the default key. Stores request timestamps in per-key files under the cache directory.

Compatible with PHP 7.4+.

Docblock Metadata

^ Tag ^ Value ^
| ''@category'' | Core Class |
| ''@author'' | Blogware Team |
| ''@license'' | MIT |
| ''@version'' | 1.0 |

Inheritance

No parent, interface or trait. This is a root type.

Constants (2)

^ Visibility ^ Name ^ Value ^ Line ^
| ''-'' | ''DEFAULT_LIMIT'' | ''60;'' | 26 |
| ''-'' | ''DEFAULT_WINDOW'' | ''60;'' | 31 |

Properties (0)

None declared.

Methods (8)

^ Visibility ^ Method ^ Summary ^ Line ^
| public | ''__construct()'' | Constructor | 45 |
| private | ''ensureCacheDir()'' | Ensure the cache directory exists and is writable | 56 |
| public | ''check()'' | Check if the current request exceeds the rate limit | 72 |
| private | ''readTimestamps()'' | Read timestamps from file, filtering out expired ones | 119 |
| private | ''writeTimestamps()'' | Write timestamps to file | 148 |
| private | ''getClientKey()'' | Generate a unique key for the current client | 167 |
| public | ''reset()'' | Reset rate limit for a specific key | 178 |
| public | ''cleanup()'' | Clean up expired rate limit files | 196 |

__construct()

public function __construct($cacheDir = null)

lines 45–49 (5)

Constructor

^ Parameter ^ Type ^ Default ^ Description ^
| ''$cacheDir'' | ''(untyped)'' | ''null'' | Override cache directory path |

ensureCacheDir()

private function ensureCacheDir()

lines 56–61 (6)

Ensure the cache directory exists and is writable

Takes no parameters.

Returns: (none declared) — void

check()

public function check($key = null, $limit = self::DEFAULT_LIMIT, $window = self::DEFAULT_WINDOW, $namespace = '')

lines 72–110 (39)

Check if the current request exceeds the rate limit

^ Parameter ^ Type ^ Default ^ Description ^
| ''$key'' | ''(untyped)'' | ''null'' | Unique identifier (default: client IP) |
| ''$limit'' | ''(untyped)'' | ''self::DEFAULT_LIMIT'' | Maximum requests allowed in the window |
| ''$window'' | ''(untyped)'' | ''self::DEFAULT_WINDOW'' | Window size in seconds |
| ''$namespace'' | ''(untyped)'' | '''''' | Optional counter namespace (e.g. 'read' vs 'write') |

Returns: (none declared) — array Result with limit, remaining, reset, retry_after, allowed

readTimestamps()

private function readTimestamps($file, $windowStart)

lines 119–138 (20)

Read timestamps from file, filtering out expired ones

^ Parameter ^ Type ^ Default ^ Description ^
| ''$file'' | ''(untyped)'' | //required// | File path |
| ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |

Returns: (none declared) — array Valid timestamps

writeTimestamps()

private function writeTimestamps($file, $timestamps, $windowStart)

lines 148–155 (8)

Write timestamps to file

^ Parameter ^ Type ^ Default ^ Description ^
| ''$file'' | ''(untyped)'' | //required// | File path |
| ''$timestamps'' | ''(untyped)'' | //required// | Timestamps to write |
| ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |

Returns: (none declared) — void

getClientKey()

private function getClientKey()

lines 167–170 (4)

Generate a unique key for the current client

Always keys on the client IP address. Previously the bucket key was derived from the attacker-controlled X-API-Key header when present, which let a client pick a fresh bucket per request and bypass the rate limit entirely.

Takes no parameters.

Returns: (none declared) — string

reset()

public function reset($key = null)

lines 178–188 (11)

Reset rate limit for a specific key

^ Parameter ^ Type ^ Default ^ Description ^
| ''$key'' | ''(untyped)'' | ''null'' | Unique identifier |

Returns: (none declared) — bool

cleanup()

public function cleanup($maxAge = 3600)

lines 196–218 (23)

Clean up expired rate limit files

^ Parameter ^ Type ^ Default ^ Description ^
| ''$maxAge'' | ''(untyped)'' | ''3600'' | Maximum age in seconds before file is considered stale |

Returns: (none declared) — int Number of files cleaned


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.

scriptlog/lib/core/ratelimiter.1790413762.txt.gz · Last modified: by admin