NestJS Enterprise Backend APIs · Leçon

Limitation du débit et régulation

Mettez en œuvre une limitation du débit et une régulation pour protéger votre API contre les abus et garantir une utilisation équitable entre les clients.

Leçon 1 sur 311 étapes

Limitation du débit et régulation est une leçon NestJS Enterprise Backend APIs gratuite sur CoddyKit. Ceci est la leçon 1 sur 3. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage NestJS Enterprise Backend APIs, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours NestJS Enterprise Backend APIs comprend 3 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

What is Rate Limiting?

Imagine a popular API. Without limits, a single user or malicious bot could flood it with requests, slowing it down for everyone or even crashing it.

Rate limiting is a technique to control the number of requests a client can make to a server within a specific time window. It's like a bouncer at a club, ensuring fair entry for all.

Protecting Your API

Rate limiting is vital for several reasons:

  • Prevent Abuse: Stops bots and malicious users from overwhelming your API.
  • Ensure Fair Usage: Guarantees that all users get a reasonable share of API resources.
  • DDoS Protection: A basic layer of defense against distributed denial-of-service attacks.
  • Cost Management: For cloud-based services, too many requests can lead to higher bills.

Rate Limiting in Action

Let's see a simple example of how a rate limiter might work behind the scenes. This script tracks requests from different "IP addresses" and allows only a certain number within a time window.

const requestCounts = new Map<string, { count: number; resetTime: number }>();
const LIMIT = 3; // Max 3 requests
const WINDOW_MS = 5000; // per 5 seconds

function checkRateLimit(ip: string): boolean {
  const now = Date.now();
  let entry = requestCounts.get(ip);

  if (!entry || now > entry.resetTime) {
    entry = { count: 1, resetTime: now + WINDOW_MS };
    requestCounts.set(ip, entry);
    return true; // Request allowed
  }

  if (entry.count < LIMIT) {
    entry.count++;
    requestCounts.set(ip, entry);
    return true; // Request allowed
  }
  return false; // Request denied
}

// Simulate requests for IP "192.168.1.1"
console.log("Req 1 (IP A):", checkRateLimit("192.168.1.1"));
console.log("Req 2 (IP A):", checkRateLimit("192.168.1.1"));
console.log("Req 3 (IP A):", checkRateLimit("192.168.1.1"));
console.log("Req 4 (IP A):", checkRateLimit("192.168.1.1")); // Denied
console.log("Req 1 (IP B):", checkRateLimit("192.168.1.2"));

What is Throttling?

While often used interchangeably, throttling has a subtle difference. Rate limiting is a hard cap: once you hit the limit, you're blocked.

Throttling, however, aims to smooth out the request rate, often by delaying requests or allowing a slower, sustained rate rather than blocking entirely. It's more about resource management and preventing a system from becoming overloaded.

Introducing NestJS Throttler

NestJS provides a robust solution for both rate limiting and throttling through the @nestjs/throttler package. It's built on top of the express-rate-limit or fastify-rate-limit packages, offering a declarative way to protect your endpoints.

The module uses a guard to intercept requests and apply rules before they reach your controller logic.

Global Throttling Configuration

First, install the package. Then, integrate ThrottlerModule into your root module (AppModule) and apply the ThrottlerGuard globally.

// 1. Install package
// npm install @nestjs/throttler

// 2. src/app.module.ts
import { Module } from '@nestjs/common';
import { ThrottlerModule, ThrottlerGuard } from '@nestjs/throttler';
import { APP_GUARD } from '@nestjs/core'; // For global guard

@Module({
  imports: [
    ThrottlerModule.forRoot([{
      ttl: 60000, // Time to live (1 minute)
      limit: 10   // Max 10 requests
    }]),
  ],
  providers: [
    {
      provide: APP_GUARD,
      useClass: ThrottlerGuard,
    },
  ],
})
export class AppModule {}

Overriding Limits per Route

Sometimes, you need different limits for specific endpoints. For example, a login route might have a stricter limit than a public data endpoint. You can override the global settings using the @Throttle() decorator.

// src/app.controller.ts
import { Controller, Get } from '@nestjs/common';
import { Throttle } from '@nestjs/throttler';

@Controller('posts')
export class PostsController {
  @Get()
  findAll(): string {
    return 'This is a public list of posts.';
  }

  @Throttle({ default: { limit: 3, ttl: 60000 } }) // 3 req/min
  @Get('protected')
  findProtected(): string {
    return 'This is a protected list of posts.';
  }

  @Throttle({ default: { limit: 1, ttl: 5000 } }) // 1 req/5s
  @Get('critical')
  findCritical(): string {
    return 'Accessing critical data.';
  }
}

Skipping Throttling

There might be routes you want to completely exempt from any throttling rules, such as health check endpoints or webhook receivers that expect high traffic. Use the @SkipThrottle() decorator for this.

// src/status.controller.ts
import { Controller, Get } from '@nestjs/common';
import { SkipThrottle } from '@nestjs/throttler';

@Controller('status')
export class StatusController {
  @SkipThrottle() // This route will ignore all throttling
  @Get('health')
  getHealth(): string {
    return 'API is healthy!';
  }

  @Get('metrics')
  getMetrics(): string {
    return 'Application metrics data.'; // This route is throttled
  }
}

Beyond IP Address

By default, the NestJS Throttler module identifies clients by their IP address. However, for authenticated users, you might want to apply limits based on their user ID, rather than their IP.

This requires extending the ThrottlerGuard and overriding the getRequestResponse method to extract a different key (e.g., from a JWT token). This ensures that a single user cannot bypass limits by changing IPs.

Understanding Throttling

You've learned about rate limiting and throttling. Let's test your understanding!

Summary of Protection

Great job! In this lesson, you learned about the importance of rate limiting and throttling to protect your NestJS APIs. You explored how to set up the @nestjs/throttler module, configure global limits, apply route-specific rules, and even skip throttling for certain endpoints.

Implementing these techniques is a crucial step in building robust and secure backend services. Keep exploring how to fine-tune these limits and integrate them with other security measures!

Gratuit pour commencer

Apprends TypeScript avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
20
Leçons
76

Questions Fréquemment Posées

La leçon « Limitation du débit et régulation » est-elle gratuite ?

Oui — le texte complet de « Limitation du débit et régulation » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours NestJS Enterprise Backend APIs, passe à CoddyKit PRO. Le cours NestJS Enterprise Backend APIs comprend 3 leçons au total.

Qu'est-ce que j'apprendrai dans « Limitation du débit et régulation » ?

Mettez en œuvre une limitation du débit et une régulation pour protéger votre API contre les abus et garantir une utilisation équitable entre les clients. Tu pratiques NestJS Enterprise Backend APIs avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer NestJS Enterprise Backend APIs ?

Aucune expérience préalable n'est requise. NestJS Enterprise Backend APIs sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 1 sur 3.

Combien de temps prend la leçon « Limitation du débit et régulation » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon NestJS Enterprise Backend APIs ?

Oui. Chaque leçon NestJS Enterprise Backend APIs inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Limitation du débit et régulation
  2. Journalisation avec Winston/Pino
  3. Supervision avec Prometheus
← Retour à NestJS Enterprise Backend APIs