Skip to content

basalt / auth/src / ThrottleStore

Interface: ThrottleStore ​

Defined in: auth/src/throttle.ts:34

Where throttle counters live. The default MemoryThrottleStore is per process; pass a shared one (RedisThrottleStore) so every replica of a cluster spends ONE budget — otherwise an attacker gets maxAttempts guesses per replica, and a lockout on one replica is not seen by the others.

Methods may be sync or async: an in-process store stays synchronous (so the count moves before any await), a network store returns promises. hit MUST be atomic — increment and read in one step — since it is what bounds a parallel burst. Keys arrive already digested (never a raw email).

Methods ​

hit() ​

> hit(key, windowMs, limit?): ThrottleWindow | Promise<ThrottleWindow>

Defined in: auth/src/throttle.ts:43

Atomically counts one attempt and returns the new state. The first hit of a key opens a fixed window of windowMs; later hits do not extend it.

limit is the caller's budget: once count >= limit the key is locked. A bounded store uses it to keep locked keys over unlocked ones when it has to evict; stores without eviction may ignore it.

Parameters ​

key ​

string

windowMs ​

number

limit? ​

number

Returns ​

ThrottleWindow | Promise<ThrottleWindow>


peek() ​

> peek(key): ThrottleWindow | Promise<ThrottleWindow | null> | null

Defined in: auth/src/throttle.ts:45

The current state without counting; null when the key has no live window.

Parameters ​

key ​

string

Returns ​

ThrottleWindow | Promise<ThrottleWindow | null> | null


release() ​

> release(key): void | Promise<void>

Defined in: auth/src/throttle.ts:47

Gives one attempt back (a successful attempt must not consume budget).

Parameters ​

key ​

string

Returns ​

void | Promise<void>


reset() ​

> reset(key): void | Promise<void>

Defined in: auth/src/throttle.ts:49

Forgets the key.

Parameters ​

key ​

string

Returns ​

void | Promise<void>

Released under the MIT License.