تحديد المعدل والحماية من القوة الغاشمة
دافعوا عن واجهات Node.js API ضد إساءة الاستخدام وحجب الخدمة وهجمات حشو بيانات الاعتماد عبر تطبيق تحديد المعدل والحماية من القوة الغاشمة
تحديد المعدل والحماية من القوة الغاشمة درس مجاني في Node.js Backend Development Bootcamp على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Node.js Backend Development Bootcamp، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Node.js Backend Development Bootcamp 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Why Limit Requests?
Without limits, a single client can hammer your API thousands of times per second — scraping data, guessing passwords, or simply overloading the server.
Rate limiting caps how many requests a client may make in a time window.
Attacks Rate Limiting Prevents
Rate limiting is a frontline defense against:
- Brute-force login attempts
- Credential stuffing with leaked passwords
- Denial-of-service floods
- Scraping and API abuse
How Counting Works
A rate limiter tracks a counter per client (usually keyed by IP). Each request increments it; when the count exceeds the limit within the window, further requests are rejected with 429 Too Many Requests.
express-rate-limit
The express-rate-limit package adds rate limiting as middleware in a few lines. Configure the window and max requests.
const rateLimit = require('express-rate-limit');
const limiter = rateLimit({
windowMs: 15 * 60 * 1000,
max: 100
});Applying the Limiter
Apply globally with app.use, or to specific routes. Once over the limit, clients automatically receive a 429 response.
app.use(limiter);
// or just protect one route:
app.use('/api/', limiter);Stricter Limits on Login
Login endpoints are prime brute-force targets, so give them a tighter limit than the rest of your API.
const loginLimiter = rateLimit({
windowMs: 10 * 60 * 1000,
max: 5,
message: 'Too many login attempts'
});
app.post('/login', loginLimiter, handler);Shared Store for Multiple Servers
The default in-memory store does not work when you run multiple instances behind a load balancer — each has its own counter. Use a shared store like Redis so limits apply across all servers.
const RedisStore = require('rate-limit-redis');
const limiter = rateLimit({
store: new RedisStore({ /* client */ }),
max: 100,
windowMs: 60000
});Trusting the Real Client IP
Behind a proxy, every request appears to come from the proxy's IP. Tell Express to trust the proxy so the limiter keys on the real client IP from X-Forwarded-For.
app.set('trust proxy', 1);Account Lockout
Beyond IP limits, track failed logins per account. After several failures, temporarily lock the account or require a CAPTCHA — defeating distributed brute-force from many IPs.
if (user.failedAttempts >= 5) {
return res.status(423).json({ error: 'Account locked' });
}Slowing Down Instead of Blocking
An alternative to hard blocks is progressive delay: each repeated request waits a little longer. The express-slow-down package adds latency rather than rejecting outright.
const slowDown = require('express-slow-down');
const speedLimiter = slowDown({
windowMs: 60000,
delayAfter: 50,
delayMs: () => 500
});Informing Clients
Good limiters send RateLimit headers telling clients their remaining quota and reset time, so well-behaved apps can back off gracefully.
const limiter = rateLimit({
max: 100,
windowMs: 60000,
standardHeaders: true
});Quick Check
Test your rate-limiting knowledge.
Recap
You learned to protect APIs from abuse:
- Rate limiting caps requests per client and returns
429when exceeded express-rate-limitadds it as middleware; use stricter limits on login- Use a Redis store across multiple servers and set
trust proxyfor real IPs - Add account lockout, progressive slow-down, and informative headers
These layers thwart brute-force, scraping, and DoS attacks.
الأسئلة الشائعة
هل درس «تحديد المعدل والحماية من القوة الغاشمة» مجاني؟
نعم — نص درس «تحديد المعدل والحماية من القوة الغاشمة» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Node.js Backend Development Bootcamp، انتقل إلى CoddyKit PRO. تتضمن دورة Node.js Backend Development Bootcamp 4 دروس في المجموع.
ماذا ستتعلم في «تحديد المعدل والحماية من القوة الغاشمة»؟
دافعوا عن واجهات Node.js API ضد إساءة الاستخدام وحجب الخدمة وهجمات حشو بيانات الاعتماد عبر تطبيق تحديد المعدل والحماية من القوة الغاشمة تتمرن على Node.js Backend Development Bootcamp مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Node.js Backend Development Bootcamp؟
لا تُشترط خبرة سابقة. Node.js Backend Development Bootcamp على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.
كم من الوقت يستغرق درس «تحديد المعدل والحماية من القوة الغاشمة»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Node.js Backend Development Bootcamp هذا؟
نعم. كل درس في Node.js Backend Development Bootcamp يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- فهم قائمة OWASP لأهم 10 مخاطر
- ممارسات البرمجة الآمنة في Node.js
- تشفير البيانات وتجزيئها
- تحديد المعدل والحماية من القوة الغاشمة