basalt / auth/src / ThrottleStore
Interface: ThrottleStore
Defined in: auth/src/throttle.ts:34
Where throttle counters live. The default MemoryThrottleStore is per process; pass a shared one (RedisThrottleStore) so every replica of a cluster spends ONE budget — otherwise an attacker gets maxAttempts guesses per replica, and a lockout on one replica is not seen by the others.
Methods may be sync or async: an in-process store stays synchronous (so the count moves before any await), a network store returns promises. hit MUST be atomic — increment and read in one step — since it is what bounds a parallel burst. Keys arrive already digested (never a raw email).
Methods
hit()
> hit(key, windowMs, limit?): ThrottleWindow | Promise<ThrottleWindow>
Defined in: auth/src/throttle.ts:43
Atomically counts one attempt and returns the new state. The first hit of a key opens a fixed window of windowMs; later hits do not extend it.
limit is the caller's budget: once count >= limit the key is locked. A bounded store uses it to keep locked keys over unlocked ones when it has to evict; stores without eviction may ignore it.
Parameters
key
string
windowMs
number
limit?
number
Returns
ThrottleWindow | Promise<ThrottleWindow>
peek()
> peek(key): ThrottleWindow | Promise<ThrottleWindow | null> | null
Defined in: auth/src/throttle.ts:45
The current state without counting; null when the key has no live window.
Parameters
key
string
Returns
ThrottleWindow | Promise<ThrottleWindow | null> | null
release()
> release(key): void | Promise<void>
Defined in: auth/src/throttle.ts:47
Gives one attempt back (a successful attempt must not consume budget).
Parameters
key
string
Returns
void | Promise<void>
reset()
> reset(key): void | Promise<void>
Defined in: auth/src/throttle.ts:49
Forgets the key.
Parameters
key
string
Returns
void | Promise<void>