basalt / auth/src / RedisThrottleStore
Class: RedisThrottleStore
Defined in: auth/src/redis-throttle.ts:64
Redis-backed ThrottleStore: the login, MFA and email-request throttles of every replica share one budget, and a lockout survives a restart. Each operation is one atomic Lua script (fixed window).
import Redis from 'ioredis'
authPlugin({ users, secret, throttleStore: new RedisThrottleStore(new Redis(url)) })Implements
Constructors
Constructor
> new RedisThrottleStore(redis, options?): RedisThrottleStore
Defined in: auth/src/redis-throttle.ts:67
Parameters
redis
options?
RedisThrottleStoreOptions = {}
Returns
RedisThrottleStore
Methods
hit()
> hit(key, windowMs): Promise<ThrottleWindow>
Defined in: auth/src/redis-throttle.ts:78
Atomically counts one attempt and returns the new state. The first hit of a key opens a fixed window of windowMs; later hits do not extend it.
limit is the caller's budget: once count >= limit the key is locked. A bounded store uses it to keep locked keys over unlocked ones when it has to evict; stores without eviction may ignore it.
Parameters
key
string
windowMs
number
Returns
Promise<ThrottleWindow>
Implementation of
peek()
> peek(key): Promise<ThrottleWindow | null>
Defined in: auth/src/redis-throttle.ts:83
The current state without counting; null when the key has no live window.
Parameters
key
string
Returns
Promise<ThrottleWindow | null>
Implementation of
release()
> release(key): Promise<void>
Defined in: auth/src/redis-throttle.ts:89
Gives one attempt back (a successful attempt must not consume budget).
Parameters
key
string
Returns
Promise<void>
Implementation of
reset()
> reset(key): Promise<void>
Defined in: auth/src/redis-throttle.ts:93
Forgets the key.
Parameters
key
string
Returns
Promise<void>