Class RateLimitPredicate
java.lang.Object
org.frontcache.guard.ratelimit.RateLimitPredicate
- All Implemented Interfaces:
GuardPredicate
The
rate: predicate - true when this request's client IP has already used up its budget
for the current window.
This is the one guard predicate with a side effect, and the pipeline assumes predicates
have none. Four consequences, each silent when it is wrong:
- It must be the LAST predicate of its rule, so the counter is fed only by requests the rest of
the condition already matched.
GuardRuleParsermoves it there (the condition is an AND, so that is semantics-preserving) and refuses a rule holding two. !rate:is refused at parse time - a negated counting predicate counts on the allowed path and then keeps evaluating.- A load-time probe context counts nothing.
GuardRuleEnginecallsrule.matches(probe)for redirect-loop detection and the exemption self-check, and those synthetic requests must not spend a real client's budget. - A dry-run rule DOES count. Dry-run is how a limit is sized before it enforces anything, so a dry-run rate rule that did not count would measure nothing.
scope=toplevel (the default): an include re-enters the engine
carrying the original visitor's address, so metering includes would spend a visitor's budget once
per fragment of the page they asked for.-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionResolves the bucket (defaulting to the rule name) and its limiter.describe()getSpec()booleantest(RequestContext context)
-
Constructor Details
-
RateLimitPredicate
-
-
Method Details
-
bind
Resolves the bucket (defaulting to the rule name) and its limiter. Called byGuardRuleParseronce the rule name is known - the predicate factory does not know it.- Returns:
- a predicate bound to its limiter
- Throws:
GuardConfigException- when the bucket cannot be allocated
-
getBucket
-
getSpec
-
test
- Specified by:
testin interfaceGuardPredicate- Parameters:
context- request context - may carry a null servlet request (async include, or a synthetic probe context used for startup loop detection)- Returns:
- true when this condition holds for the request
-
describe
- Specified by:
describein interfaceGuardPredicate- Returns:
- the predicate as written in guard-rules.conf (used by logs and the admin API)
-