Skip to content

basalt / auth/src / LoginThrottle

Class: LoginThrottle ​

Defined in: auth/src/throttle.ts:203

Brute-force guard: counts failed logins per identifier (email) within a fixed window and locks the account once the budget is spent. A successful login clears the counter. Counters live in a ThrottleStore: in memory per process by default, or shared across replicas (Redis).

Identifiers are handed to the store as SHA-256 digests (fixed size, never the raw email).

Use reserve before verifying credentials: it counts the attempt atomically (synchronously with the memory store, in one Redis script with a shared one), so a parallel burst cannot run more verifications than the budget allows. release gives the reservation back on success.

Every method returns synchronously with a synchronous store (the default) and a promise otherwise; await the result when the store may be async.

Constructors ​

Constructor ​

> new LoginThrottle(options?): LoginThrottle

Defined in: auth/src/throttle.ts:209

Parameters ​

options? ​

LoginThrottleOptions = {}

Returns ​

LoginThrottle

Accessors ​

size ​

Get Signature ​

> get size(): number

Defined in: auth/src/throttle.ts:222

Number of identifiers currently tracked (in-memory store only; 0 otherwise).

Returns ​

number

Methods ​

assertAllowed() ​

> assertAllowed(key): Awaitable<void>

Defined in: auth/src/throttle.ts:236

Throws AccountLockedError when the key is currently locked.

Parameters ​

key ​

string

Returns ​

Awaitable<void>


recordFailure() ​

> recordFailure(key): Awaitable<void>

Defined in: auth/src/throttle.ts:242

Parameters ​

key ​

string

Returns ​

Awaitable<void>


release() ​

> release(key): Awaitable<void>

Defined in: auth/src/throttle.ts:258

Returns one reservation (a successful attempt must not consume budget).

Parameters ​

key ​

string

Returns ​

Awaitable<void>


reserve() ​

> reserve(key): Awaitable<void>

Defined in: auth/src/throttle.ts:251

Atomically counts this attempt and throws AccountLockedError when it exceeds the budget. Pair with release on success; a failure simply keeps the reservation.

Parameters ​

key ​

string

Returns ​

Awaitable<void>


reset() ​

> reset(key): Awaitable<void>

Defined in: auth/src/throttle.ts:262

Parameters ​

key ​

string

Returns ​

Awaitable<void>


retainedKeyChars() ​

> retainedKeyChars(): number

Defined in: auth/src/throttle.ts:227

Total characters retained in keys — diagnostics for memory bounds (in-memory store only).

Returns ​

number

Released under the MIT License.