Class RateLimitPredicate

java.lang.Object
org.frontcache.guard.ratelimit.RateLimitPredicate
All Implemented Interfaces:
GuardPredicate

public class RateLimitPredicate extends Object implements GuardPredicate
The rate: predicate - true when this request's client IP has already used up its budget for the current window. This is the one guard predicate with a side effect, and the pipeline assumes predicates have none. Four consequences, each silent when it is wrong:
  1. It must be the LAST predicate of its rule, so the counter is fed only by requests the rest of the condition already matched. GuardRuleParser moves it there (the condition is an AND, so that is semantics-preserving) and refuses a rule holding two.
  2. !rate: is refused at parse time - a negated counting predicate counts on the allowed path and then keeps evaluating.
  3. A load-time probe context counts nothing. GuardRuleEngine calls rule.matches(probe) for redirect-loop detection and the exemption self-check, and those synthetic requests must not spend a real client's budget.
  4. A dry-run rule DOES count. Dry-run is how a limit is sized before it enforces anything, so a dry-run rate rule that did not count would measure nothing.
Counting also stops at scope=toplevel (the default): an include re-enters the engine carrying the original visitor's address, so metering includes would spend a visitor's budget once per fragment of the page they asked for.
  • Constructor Details

    • RateLimitPredicate

      public RateLimitPredicate(RateLimitSpec spec)
  • Method Details

    • bind

      public RateLimitPredicate bind(String ruleName)
      Resolves the bucket (defaulting to the rule name) and its limiter. Called by GuardRuleParser once the rule name is known - the predicate factory does not know it.
      Returns:
      a predicate bound to its limiter
      Throws:
      GuardConfigException - when the bucket cannot be allocated
    • getBucket

      public String getBucket()
    • getSpec

      public RateLimitSpec getSpec()
    • test

      public boolean test(RequestContext context)
      Specified by:
      test in interface GuardPredicate
      Parameters:
      context - request context - may carry a null servlet request (async include, or a synthetic probe context used for startup loop detection)
      Returns:
      true when this condition holds for the request
    • describe

      public String describe()
      Specified by:
      describe in interface GuardPredicate
      Returns:
      the predicate as written in guard-rules.conf (used by logs and the admin API)