Skip to content

basalt / http/src / RateLimitKey

Type Alias: RateLimitKey ​

> RateLimitKey = "ip" | "user" | "tenant" | "user+tenant" | ((context) => string | undefined | null)

Defined in: http/src/security.ts:185

Who a per-route bucket belongs to (meta.rateLimit.key):

  • 'ip' (default) — the client address (request.ip), as before.
  • 'user' — ctx().user.id: users behind one NAT/proxy no longer share a budget.
  • 'tenant' — ctx().tenant.id: every user of a tenant shares one budget.
  • 'user+tenant' — one budget per user per tenant.
  • a function of ctx() returning the bucket id.

Resolved after enrichers ran, so auth/tenancy have set ctx(). When the id is missing (anonymous caller, no tenant resolved, the function returns nothing) the bucket falls back to the client IP, never mixed with identified callers' buckets (those are namespaced user:/tenant:/key:).

The IP itself can be missing too: when the adapter could not resolve request.ip (Hono on a runtime without getClientIp, a hand-built pipeline), every such request shares ONE bucket, unknown — deliberately fail-closed, since the alternative would be a bucket per spoofable header. Resolve the address in the adapter to get per-client buckets back.

Released under the MIT License.