This is an old revision of the document!
Table of Contents
RateLimiter
Layer: Core · Source: lib/core/RateLimiter.php:21 (lines 21–219)
class RateLimiter
RateLimiter
File-based sliding window rate limiter for API endpoints. Uses IP address as the default key. Stores request timestamps in per-key files under the cache directory.
Compatible with PHP 7.4+.
Docblock Metadata
^ Tag ^ Value ^ | ''@category'' | Core Class | | ''@author'' | Blogware Team | | ''@license'' | MIT | | ''@version'' | 1.0 |
Inheritance
No parent, interface or trait. This is a root type.
Constants (2)
^ Visibility ^ Name ^ Value ^ Line ^ | ''-'' | ''DEFAULT_LIMIT'' | ''60;'' | 26 | | ''-'' | ''DEFAULT_WINDOW'' | ''60;'' | 31 |
Properties (0)
None declared.
Methods (8)
^ Visibility ^ Method ^ Summary ^ Line ^ | public | ''__construct()'' | Constructor | 45 | | private | ''ensureCacheDir()'' | Ensure the cache directory exists and is writable | 56 | | public | ''check()'' | Check if the current request exceeds the rate limit | 72 | | private | ''readTimestamps()'' | Read timestamps from file, filtering out expired ones | 119 | | private | ''writeTimestamps()'' | Write timestamps to file | 148 | | private | ''getClientKey()'' | Generate a unique key for the current client | 167 | | public | ''reset()'' | Reset rate limit for a specific key | 178 | | public | ''cleanup()'' | Clean up expired rate limit files | 196 |
__construct()
public function __construct($cacheDir = null)
lines 45–49 (5)
Constructor
^ Parameter ^ Type ^ Default ^ Description ^ | ''$cacheDir'' | ''(untyped)'' | ''null'' | Override cache directory path |
ensureCacheDir()
private function ensureCacheDir()
lines 56–61 (6)
Ensure the cache directory exists and is writable
Takes no parameters.
Returns: (none declared) — void
check()
public function check($key = null, $limit = self::DEFAULT_LIMIT, $window = self::DEFAULT_WINDOW, $namespace = '')
lines 72–110 (39)
Check if the current request exceeds the rate limit
^ Parameter ^ Type ^ Default ^ Description ^ | ''$key'' | ''(untyped)'' | ''null'' | Unique identifier (default: client IP) | | ''$limit'' | ''(untyped)'' | ''self::DEFAULT_LIMIT'' | Maximum requests allowed in the window | | ''$window'' | ''(untyped)'' | ''self::DEFAULT_WINDOW'' | Window size in seconds | | ''$namespace'' | ''(untyped)'' | '''''' | Optional counter namespace (e.g. 'read' vs 'write') |
Returns: (none declared) — array Result with limit, remaining, reset, retry_after, allowed
readTimestamps()
private function readTimestamps($file, $windowStart)
lines 119–138 (20)
Read timestamps from file, filtering out expired ones
^ Parameter ^ Type ^ Default ^ Description ^ | ''$file'' | ''(untyped)'' | //required// | File path | | ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |
Returns: (none declared) — array Valid timestamps
writeTimestamps()
private function writeTimestamps($file, $timestamps, $windowStart)
lines 148–155 (8)
Write timestamps to file
^ Parameter ^ Type ^ Default ^ Description ^ | ''$file'' | ''(untyped)'' | //required// | File path | | ''$timestamps'' | ''(untyped)'' | //required// | Timestamps to write | | ''$windowStart'' | ''(untyped)'' | //required// | Earliest valid timestamp |
Returns: (none declared) — void
getClientKey()
private function getClientKey()
lines 167–170 (4)
Generate a unique key for the current client
Always keys on the client IP address. Previously the bucket key was derived from the attacker-controlled X-API-Key header when present, which let a client pick a fresh bucket per request and bypass the rate limit entirely.
Takes no parameters.
Returns: (none declared) — string
reset()
public function reset($key = null)
lines 178–188 (11)
Reset rate limit for a specific key
^ Parameter ^ Type ^ Default ^ Description ^ | ''$key'' | ''(untyped)'' | ''null'' | Unique identifier |
Returns: (none declared) — bool
cleanup()
public function cleanup($maxAge = 3600)
lines 196–218 (23)
Clean up expired rate limit files
^ Parameter ^ Type ^ Default ^ Description ^ | ''$maxAge'' | ''(untyped)'' | ''3600'' | Maximum age in seconds before file is considered stale |
Returns: (none declared) — int Number of files cleaned
This page is generated from source by 'tools/gendoc'. Edits will be overwritten.
