レート制限と総当たり攻撃対策
Redisのような高速ストアを使ったレート制限、アカウントロックアウト、指数バックオフで、SaaSの認証機能とAPIを悪用から守ります。
「レート制限と総当たり攻撃対策」はCoddyKit上の無料AI Powered SaaS: Stripe + Auth + Billing + Deployレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはAI Powered SaaS: Stripe + Auth + Billing + Deploy学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 AI Powered SaaS: Stripe + Auth + Billing + Deployコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Why Rate Limit?
Without limits, attackers can hammer your login endpoint to guess passwords, scrape data, or run up costs on metered APIs. Rate limiting caps how many requests a client can make in a window.
Identifying the Client
Limits are keyed on something that identifies the caller: an IP address, a user ID, or an API key. Choose the key based on what you are protecting.
const key = 'login:' + (userId ?? clientIp);The Fixed Window Algorithm
The simplest method counts requests per fixed time window. If the count exceeds the limit, reject until the window resets.
// allow 5 requests per 60 seconds
if (count > 5) return reject();Counting in Redis
Redis is ideal: INCR bumps a counter atomically, and a TTL auto-expires the window. The first request sets the expiry.
const n = await redis.incr(key);
if (n === 1) await redis.expire(key, 60);
if (n > 5) throw new Error('Too many requests');Sliding Window & Token Bucket
Fixed windows allow bursts at the edges. Sliding window smooths this, and token bucket permits short bursts while enforcing an average rate. Libraries like Upstash Ratelimit implement these for you.
import { Ratelimit } from '@upstash/ratelimit';
const rl = new Ratelimit({ redis, limiter: Ratelimit.slidingWindow(5, '60 s') });Applying in Middleware
Centralize limiting in Next.js middleware so it runs before every matched request.
export async function middleware(req) {
const { success } = await rl.limit(req.ip ?? 'anon');
if (!success) return new Response('Rate limited', { status: 429 });
}Returning 429 Properly
When limited, respond with status 429 and a Retry-After header telling clients when to try again.
return new Response('Too many requests', {
status: 429,
headers: { 'Retry-After': '60' }
});Account Lockout
For login specifically, track failed attempts per account. After several failures, temporarily lock the account to stop targeted brute force.
const fails = await redis.incr('fail:' + email);
if (fails >= 5) await redis.expire('lock:' + email, 900);Exponential Backoff
Increase the delay after each failure: 1s, 2s, 4s, 8s. This frustrates automated guessing while barely affecting legitimate users.
const delay = Math.min(2 ** fails, 60) * 1000;Avoiding False Positives
Be careful not to punish real users:
- Shared office IPs share a limit — prefer per-user keys when authenticated
- Reset counters on success
- Set generous limits for normal usage
Best Practices
Protect endpoints well:
- Key limits on IP, user, or API key
- Use Redis with sliding window or token bucket
- Return 429 with Retry-After
- Add lockout and backoff for login
Quick Check
Test your rate-limiting knowledge.
Recap
You learned to defend against abuse:
- Key rate limits on IP, user, or API key
- Count with Redis
INCRand TTL, or use sliding window libraries - Return
429withRetry-After - Add account lockout and exponential backoff for logins
Your auth and APIs now resist brute force and flooding.
AI チューターと学ぶ AI Powered SaaS: Stripe + Auth + Billing + Deploy — 無料
ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。
- コース
- 12
- レッスン
- 48
よくある質問
「レート制限と総当たり攻撃対策」レッスンは無料ですか?
はい。「レート制限と総当たり攻撃対策」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、AI Powered SaaS: Stripe + Auth + Billing + Deployコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 AI Powered SaaS: Stripe + Auth + Billing + Deployコースには全4レッスンが含まれています。
「レート制限と総当たり攻撃対策」で何を学びますか?
Redisのような高速ストアを使ったレート制限、アカウントロックアウト、指数バックオフで、SaaSの認証機能とAPIを悪用から守ります。 ブラウザで直接実行するハンズオンコードでAI Powered SaaS: Stripe + Auth + Billing + Deployを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
AI Powered SaaS: Stripe + Auth + Billing + Deployを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのAI Powered SaaS: Stripe + Auth + Billing + Deployは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。
「レート制限と総当たり攻撃対策」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このAI Powered SaaS: Stripe + Auth + Billing + Deployレッスンでコードを書いて実行できますか?
はい。すべてのAI Powered SaaS: Stripe + Auth + Billing + Deployレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- OAuth 2.0の統合
- 多要素認証(MFA)
- ロールベースアクセス制御(RBAC)
- レート制限と総当たり攻撃対策