basalt / http/src / MemoryRateLimitStoreOptions
Interface: MemoryRateLimitStoreOptions
Defined in: http/src/security.ts:25
Properties
clock?
> optional clock?: () => number
Defined in: http/src/security.ts:26
Returns
number
maxEntries?
> optional maxEntries?: number
Defined in: http/src/security.ts:41
Most open buckets kept at once (default 100 000). Past it, expired buckets are swept and, if the store is still full, the oldest windows are evicted first — so a flood of distinct client addresses (IPv6 makes them cheap) costs bounded memory instead of growing the process until it dies. Evicting a live window resets that client's count, so size it well above your real distinct-client count per window; use RedisRateLimitStore across instances.
A bucket that has used up its limit is never evicted: it is held until its window ends, so a flood of fresh keys cannot free a limited client early. Those buckets are the only ones allowed past the cap — each cost its client a full limit of requests, and each goes when its window does.
sweepIntervalMs?
> optional sweepIntervalMs?: number
Defined in: http/src/security.ts:43
How often, at most, a hit sweeps every expired bucket (default 60 000 ms).