basalt / auth/src / LoginThrottle
Class: LoginThrottle
Defined in: auth/src/throttle.ts:203
Brute-force guard: counts failed logins per identifier (email) within a fixed window and locks the account once the budget is spent. A successful login clears the counter. Counters live in a ThrottleStore: in memory per process by default, or shared across replicas (Redis).
Identifiers are handed to the store as SHA-256 digests (fixed size, never the raw email).
Use reserve before verifying credentials: it counts the attempt atomically (synchronously with the memory store, in one Redis script with a shared one), so a parallel burst cannot run more verifications than the budget allows. release gives the reservation back on success.
Every method returns synchronously with a synchronous store (the default) and a promise otherwise; await the result when the store may be async.
Constructors
Constructor
> new LoginThrottle(options?): LoginThrottle
Defined in: auth/src/throttle.ts:209
Parameters
options?
LoginThrottleOptions = {}
Returns
LoginThrottle
Accessors
size
Get Signature
> get size(): number
Defined in: auth/src/throttle.ts:222
Number of identifiers currently tracked (in-memory store only; 0 otherwise).
Returns
number
Methods
assertAllowed()
> assertAllowed(key): Awaitable<void>
Defined in: auth/src/throttle.ts:236
Throws AccountLockedError when the key is currently locked.
Parameters
key
string
Returns
Awaitable<void>
recordFailure()
> recordFailure(key): Awaitable<void>
Defined in: auth/src/throttle.ts:242
Parameters
key
string
Returns
Awaitable<void>
release()
> release(key): Awaitable<void>
Defined in: auth/src/throttle.ts:258
Returns one reservation (a successful attempt must not consume budget).
Parameters
key
string
Returns
Awaitable<void>
reserve()
> reserve(key): Awaitable<void>
Defined in: auth/src/throttle.ts:251
Atomically counts this attempt and throws AccountLockedError when it exceeds the budget. Pair with release on success; a failure simply keeps the reservation.
Parameters
key
string
Returns
Awaitable<void>
reset()
> reset(key): Awaitable<void>
Defined in: auth/src/throttle.ts:262
Parameters
key
string
Returns
Awaitable<void>
retainedKeyChars()
> retainedKeyChars(): number
Defined in: auth/src/throttle.ts:227
Total characters retained in keys — diagnostics for memory bounds (in-memory store only).
Returns
number