Secure Coding & OWASP Top 10 for Backend · 课时

接口限流与节流

学习限流如何保护接口免受滥用、暴力破解和拒绝服务攻击,并了解如何实现令牌桶和滑动窗口策略。

第 4 / 4 课13 个步骤

接口限流与节流 是 CoddyKit 上的免费 Secure Coding & OWASP Top 10 for Backend 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Secure Coding & OWASP Top 10 for Backend 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Secure Coding & OWASP Top 10 for Backend 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Why Rate Limiting?

Rate limiting caps how many requests a client can make in a time window. It protects APIs from brute-force attacks, scraping, accidental loops, and denial-of-service.

It is a key control listed under API security best practices.

Throttling vs Limiting

Rate limiting rejects requests over a hard cap; throttling slows them down (queuing or delaying) instead of rejecting outright. Both manage load and abuse, often used together.

What to Limit On

Choose a key to count requests against:

  • API key or user ID for authenticated traffic
  • IP address for anonymous traffic
  • Endpoint sensitivity (stricter limits on login)

Combining keys gives finer control and resists simple bypasses.

Fixed Window

The simplest approach counts requests in a fixed time window, resetting the counter each period. It is easy but allows bursts at window edges (twice the limit across a boundary).

import time

window = {}
LIMIT = 5
PERIOD = 60

def allow(key):
    now = int(time.time() // PERIOD)
    count = window.get((key, now), 0)
    if count >= LIMIT:
        return False
    window[(key, now)] = count + 1
    return True

Token Bucket

The token bucket refills tokens at a steady rate up to a capacity. Each request consumes a token; an empty bucket means the request is rejected. It allows controlled bursts while enforcing an average rate.

import time

class TokenBucket:
    def __init__(self, rate, capacity):
        self.rate = rate
        self.capacity = capacity
        self.tokens = capacity
        self.last = time.time()
    def allow(self):
        now = time.time()
        self.tokens = min(self.capacity, self.tokens + (now - self.last) * self.rate)
        self.last = now
        if self.tokens >= 1:
            self.tokens -= 1
            return True
        return False

Sliding Window

The sliding window tracks timestamps of recent requests and counts only those within the last N seconds. It avoids the burst problem of fixed windows at the cost of more bookkeeping.

Distributed Rate Limiting

With multiple servers, counters must be shared. A central store like Redis holds the counters so limits apply across the whole cluster, not per instance. Use atomic operations to avoid race conditions.

Communicating Limits

Tell clients about their limits with response headers so well-behaved clients can back off.

headers = {
    'X-RateLimit-Limit': '100',
    'X-RateLimit-Remaining': '42',
    'X-RateLimit-Reset': '1717000000',
    'Retry-After': '30',
}
for k, v in headers.items():
    print(k + ': ' + v)

Status Codes

Return 429 Too Many Requests when a client exceeds the limit, ideally with a Retry-After header. This is the standard signal clients and SDKs expect.

Protecting Sensitive Endpoints

Apply stricter limits to high-risk endpoints like login, password reset, and OTP verification. Tight limits here directly blunt brute-force and credential-stuffing attacks.

  • Login: a few attempts per minute
  • Password reset: a few per hour
  • General reads: generous limits

Avoiding Pitfalls

Watch for bypasses: rotating IPs, missing limits on some routes, and limits that reset on server restart. Place rate limiting at the gateway or middleware layer so every route is covered consistently.

Quick Check

Test your understanding of rate limiting.

Recap

You learned why APIs need rate limiting, how to choose a limiting key, and the trade-offs of fixed-window, token-bucket, and sliding-window strategies. You also saw distributed limiting with Redis, the 429 response, and stricter limits for sensitive endpoints.

免费开始

用 AI 导师学习 Secure Coding & OWASP Top 10 for Backend — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
12
课程
48

常见问题解答

「接口限流与节流」课时是免费的吗?

是的 — 「接口限流与节流」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Secure Coding & OWASP Top 10 for Backend 课程的其余内容,请升级到 CoddyKit PRO。 Secure Coding & OWASP Top 10 for Backend 课程共包含 4 节课。

「接口限流与节流」这节课中我会学到什么?

学习限流如何保护接口免受滥用、暴力破解和拒绝服务攻击,并了解如何实现令牌桶和滑动窗口策略。 你通过在浏览器中直接运行的动手代码来练习 Secure Coding & OWASP Top 10 for Backend,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Secure Coding & OWASP Top 10 for Backend 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Secure Coding & OWASP Top 10 for Backend 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。

「接口限流与节流」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Secure Coding & OWASP Top 10 for Backend 课中编写并运行代码吗?

能。每节 Secure Coding & OWASP Top 10 for Backend 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 设计安全的 RESTful API
  2. GraphQL API 安全
  3. 防止 SSRF 攻击
  4. 接口限流与节流
← 返回 Secure Coding & OWASP Top 10 for Backend