Skip to content

basalt / http/src / MemoryRateLimitStoreOptions

Interface: MemoryRateLimitStoreOptions ​

Defined in: http/src/security.ts:25

Properties ​

clock? ​

> optional clock?: () => number

Defined in: http/src/security.ts:26

Returns ​

number


maxEntries? ​

> optional maxEntries?: number

Defined in: http/src/security.ts:41

Most open buckets kept at once (default 100 000). Past it, expired buckets are swept and, if the store is still full, the oldest windows are evicted first — so a flood of distinct client addresses (IPv6 makes them cheap) costs bounded memory instead of growing the process until it dies. Evicting a live window resets that client's count, so size it well above your real distinct-client count per window; use RedisRateLimitStore across instances.

A bucket that has used up its limit is never evicted: it is held until its window ends, so a flood of fresh keys cannot free a limited client early. Those buckets are the only ones allowed past the cap — each cost its client a full limit of requests, and each goes when its window does.


sweepIntervalMs? ​

> optional sweepIntervalMs?: number

Defined in: http/src/security.ts:43

How often, at most, a hit sweeps every expired bucket (default 60 000 ms).

Released under the MIT License.