Pembatasan Laju & Pembatasan Kecepatan API
Pelajari cara pembatasan laju melindungi API dari penyalahgunaan, brute force, dan penolakan layanan, serta cara menerapkan strategi ember token dan jendela geser.
Pembatasan Laju & Pembatasan Kecepatan API adalah pelajaran Secure Coding & OWASP Top 10 for Backend gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Secure Coding & OWASP Top 10 for Backend, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Why Rate Limiting?
Rate limiting caps how many requests a client can make in a time window. It protects APIs from brute-force attacks, scraping, accidental loops, and denial-of-service.
It is a key control listed under API security best practices.
Throttling vs Limiting
Rate limiting rejects requests over a hard cap; throttling slows them down (queuing or delaying) instead of rejecting outright. Both manage load and abuse, often used together.
What to Limit On
Choose a key to count requests against:
- API key or user ID for authenticated traffic
- IP address for anonymous traffic
- Endpoint sensitivity (stricter limits on login)
Combining keys gives finer control and resists simple bypasses.
Fixed Window
The simplest approach counts requests in a fixed time window, resetting the counter each period. It is easy but allows bursts at window edges (twice the limit across a boundary).
import time
window = {}
LIMIT = 5
PERIOD = 60
def allow(key):
now = int(time.time() // PERIOD)
count = window.get((key, now), 0)
if count >= LIMIT:
return False
window[(key, now)] = count + 1
return TrueToken Bucket
The token bucket refills tokens at a steady rate up to a capacity. Each request consumes a token; an empty bucket means the request is rejected. It allows controlled bursts while enforcing an average rate.
import time
class TokenBucket:
def __init__(self, rate, capacity):
self.rate = rate
self.capacity = capacity
self.tokens = capacity
self.last = time.time()
def allow(self):
now = time.time()
self.tokens = min(self.capacity, self.tokens + (now - self.last) * self.rate)
self.last = now
if self.tokens >= 1:
self.tokens -= 1
return True
return FalseSliding Window
The sliding window tracks timestamps of recent requests and counts only those within the last N seconds. It avoids the burst problem of fixed windows at the cost of more bookkeeping.
Distributed Rate Limiting
With multiple servers, counters must be shared. A central store like Redis holds the counters so limits apply across the whole cluster, not per instance. Use atomic operations to avoid race conditions.
Communicating Limits
Tell clients about their limits with response headers so well-behaved clients can back off.
headers = {
'X-RateLimit-Limit': '100',
'X-RateLimit-Remaining': '42',
'X-RateLimit-Reset': '1717000000',
'Retry-After': '30',
}
for k, v in headers.items():
print(k + ': ' + v)Status Codes
Return 429 Too Many Requests when a client exceeds the limit, ideally with a Retry-After header. This is the standard signal clients and SDKs expect.
Protecting Sensitive Endpoints
Apply stricter limits to high-risk endpoints like login, password reset, and OTP verification. Tight limits here directly blunt brute-force and credential-stuffing attacks.
- Login: a few attempts per minute
- Password reset: a few per hour
- General reads: generous limits
Avoiding Pitfalls
Watch for bypasses: rotating IPs, missing limits on some routes, and limits that reset on server restart. Place rate limiting at the gateway or middleware layer so every route is covered consistently.
Quick Check
Test your understanding of rate limiting.
Recap
You learned why APIs need rate limiting, how to choose a limiting key, and the trade-offs of fixed-window, token-bucket, and sliding-window strategies. You also saw distributed limiting with Redis, the 429 response, and stricter limits for sensitive endpoints.
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pembatasan Laju & Pembatasan Kecepatan API” gratis?
Ya — teks lengkap “Pembatasan Laju & Pembatasan Kecepatan API” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Secure Coding & OWASP Top 10 for Backend, upgrade ke CoddyKit PRO. Kursus Secure Coding & OWASP Top 10 for Backend mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pembatasan Laju & Pembatasan Kecepatan API”?
Pelajari cara pembatasan laju melindungi API dari penyalahgunaan, brute force, dan penolakan layanan, serta cara menerapkan strategi ember token dan jendela geser. Kamu berlatih Secure Coding & OWASP Top 10 for Backend dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Secure Coding & OWASP Top 10 for Backend?
Tidak diperlukan pengalaman sebelumnya. Secure Coding & OWASP Top 10 for Backend di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.
Berapa lama pelajaran “Pembatasan Laju & Pembatasan Kecepatan API” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Secure Coding & OWASP Top 10 for Backend ini?
Ya. Setiap pelajaran Secure Coding & OWASP Top 10 for Backend menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Merancang API RESTful yang Aman
- Keamanan API GraphQL
- Mencegah Serangan SSRF
- Pembatasan Laju & Pembatasan Kecepatan API