Documentation
¶
Overview ¶
Package memorylimiter is the in-process sliding-window rate limiter over ratelimit.Limit buckets: AuthKit's limiter without Redis, and the Redis limiter's fallback.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Limiter ¶
type Limiter struct {
// contains filtered or unexported fields
}
Limiter is an in-process sliding-window rate limiter.
func (*Limiter) Allow ¶ added in v1.1.0
Allow uses a sliding window over the bucket's duration, pruning the touched bucket's expired entries. Buckets whose keys go idle are reclaimed only by Cleanup, so StartCleanup must run.
func (*Limiter) Cleanup ¶
Cleanup prunes expired timestamps from every bucket and deletes buckets that have no live timestamps left, then returns the number of buckets still retained. It is safe to call concurrently with Allow and is the mechanism that bounds memory when the limiter is keyed on a high-cardinality, attacker-influenced dimension (per-IP, per-identifier): without it, every distinct key leaves behind a bucket that is never revisited.
func (*Limiter) StartCleanup ¶
StartCleanup runs Cleanup on the given interval until ctx is cancelled. It returns immediately, spawning a single background goroutine; cancel ctx to stop it. A non-positive interval is treated as a no-op (returns without starting a goroutine) so misconfiguration can't spin a hot loop.