Pembatasan Laju dan Perlindungan dari Serangan Brute-Force
Lindungi autentikasi dan API SaaS Anda dari penyalahgunaan dengan pembatasan laju, penguncian akun, dan jeda eksponensial menggunakan penyimpanan cepat seperti Redis.
Pembatasan Laju dan Perlindungan dari Serangan Brute-Force adalah pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar AI Powered SaaS: Stripe + Auth + Billing + Deploy, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Why Rate Limit?
Without limits, attackers can hammer your login endpoint to guess passwords, scrape data, or run up costs on metered APIs. Rate limiting caps how many requests a client can make in a window.
Identifying the Client
Limits are keyed on something that identifies the caller: an IP address, a user ID, or an API key. Choose the key based on what you are protecting.
const key = 'login:' + (userId ?? clientIp);The Fixed Window Algorithm
The simplest method counts requests per fixed time window. If the count exceeds the limit, reject until the window resets.
// allow 5 requests per 60 seconds
if (count > 5) return reject();Counting in Redis
Redis is ideal: INCR bumps a counter atomically, and a TTL auto-expires the window. The first request sets the expiry.
const n = await redis.incr(key);
if (n === 1) await redis.expire(key, 60);
if (n > 5) throw new Error('Too many requests');Sliding Window & Token Bucket
Fixed windows allow bursts at the edges. Sliding window smooths this, and token bucket permits short bursts while enforcing an average rate. Libraries like Upstash Ratelimit implement these for you.
import { Ratelimit } from '@upstash/ratelimit';
const rl = new Ratelimit({ redis, limiter: Ratelimit.slidingWindow(5, '60 s') });Applying in Middleware
Centralize limiting in Next.js middleware so it runs before every matched request.
export async function middleware(req) {
const { success } = await rl.limit(req.ip ?? 'anon');
if (!success) return new Response('Rate limited', { status: 429 });
}Returning 429 Properly
When limited, respond with status 429 and a Retry-After header telling clients when to try again.
return new Response('Too many requests', {
status: 429,
headers: { 'Retry-After': '60' }
});Account Lockout
For login specifically, track failed attempts per account. After several failures, temporarily lock the account to stop targeted brute force.
const fails = await redis.incr('fail:' + email);
if (fails >= 5) await redis.expire('lock:' + email, 900);Exponential Backoff
Increase the delay after each failure: 1s, 2s, 4s, 8s. This frustrates automated guessing while barely affecting legitimate users.
const delay = Math.min(2 ** fails, 60) * 1000;Avoiding False Positives
Be careful not to punish real users:
- Shared office IPs share a limit — prefer per-user keys when authenticated
- Reset counters on success
- Set generous limits for normal usage
Best Practices
Protect endpoints well:
- Key limits on IP, user, or API key
- Use Redis with sliding window or token bucket
- Return 429 with Retry-After
- Add lockout and backoff for login
Quick Check
Test your rate-limiting knowledge.
Recap
You learned to defend against abuse:
- Key rate limits on IP, user, or API key
- Count with Redis
INCRand TTL, or use sliding window libraries - Return
429withRetry-After - Add account lockout and exponential backoff for logins
Your auth and APIs now resist brute force and flooding.
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pembatasan Laju dan Perlindungan dari Serangan Brute-Force” gratis?
Ya — teks lengkap “Pembatasan Laju dan Perlindungan dari Serangan Brute-Force” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy, upgrade ke CoddyKit PRO. Kursus AI Powered SaaS: Stripe + Auth + Billing + Deploy mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pembatasan Laju dan Perlindungan dari Serangan Brute-Force”?
Lindungi autentikasi dan API SaaS Anda dari penyalahgunaan dengan pembatasan laju, penguncian akun, dan jeda eksponensial menggunakan penyimpanan cepat seperti Redis. Kamu berlatih AI Powered SaaS: Stripe + Auth + Billing + Deploy dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai AI Powered SaaS: Stripe + Auth + Billing + Deploy?
Tidak diperlukan pengalaman sebelumnya. AI Powered SaaS: Stripe + Auth + Billing + Deploy di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.
Berapa lama pelajaran “Pembatasan Laju dan Perlindungan dari Serangan Brute-Force” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy ini?
Ya. Setiap pelajaran AI Powered SaaS: Stripe + Auth + Billing + Deploy menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Integrasi OAuth 2.0
- Autentikasi Multifaktor (MFA)
- Kontrol Akses Berbasis Peran (RBAC)
- Pembatasan Laju dan Perlindungan dari Serangan Brute-Force