Skip to main content

RateLimiter middlewares

Initial configuration​

To begin using the rate-limiter middlewares, you'll need to create and configure a RateLimiterFactory instance:

./samples/rate-limiter.ts
import { RateLimiterFactory } from "eridu-tech/rate-limiter";
import { DatabaseRateLimiterAdapter } from "eridu-tech/rate-limiter/database-rate-limiter-adapter";
import { MemoryRateLimiterStorageAdapter } from "eridu-tech/rate-limiter/memory-rate-limiter-storage-adapter";

export const rateLimiterFactory = new RateLimiterFactory({
adapter: new DatabaseRateLimiterAdapter({
adapter: new MemoryRateLimiterStorageAdapter(),
}),
});

withRateLimiterFactory middleware​

The RateLimiter middleware wraps function calls with a rate limiter, controlling how many times a function can be invoked within a configured policy window. Each unique key (derived from the function's arguments) gets its own rate limit counter. Once the limit is reached, further invocations are blocked until the policy permits attempts again.

Usage​

./samples/with-rate-limiter.ts
import { withRateLimiterFactory } from "eridu-tech/rate-limiter/middlewares";
import { use } from "eridu-tech/middleware";
import { rateLimiterFactory } from "./rate-limiter.js";

const withRateLimiter = withRateLimiterFactory(rateLimiterFactory);

const fetchHandler = async (request: Request): Promise<Response> => {
// ... handle the request
return new Response("OK");
};

// Wrap with rate limiter — max 10 calls per window
const rateLimitedCall = use(
fetchHandler,
withRateLimiter({
key: ([req]) => `api:${String(req.headers.get("x-ip"))}`,
limit: 10,
}),
);

await rateLimitedCall(
new Request("/url", {
method: "POST",
}),
);
info

Here is a complete list of settings for the withRateLimiter function.

Settings​

OptionTypeDescription
keyInvocable<TParameters, string>A function that produces the rate-limiter key from the wrapped function's arguments. Each unique key gets its own rate-limit counter
limitnumberMaximum number of invocations allowed within the configured window
onlyErrorbooleanWhen true, only failed (errored) invocations count toward the rate limit. Defaults to false
errorPolicyErrorPolicyDetermines which errors count toward the rate limit. Defaults to treating all errors as failures

Further information​

For further information refer to eridu-tech/rate-limiter API docs.