The question was the rate limit one.
You need to use an in-memory rate limiter to protect an API endpoint.
The rate limiter is initialized with a value that represents the maximum number of requests allowed per second.
Every time a request hits the API endpoint, it first asks the rate limiter whether there is still capacity to handle the request, and the rate limiter decides based on that whether to accept or reject it.
Example (at most 2 requests per second):
09:30:05.250 PASS
09:30:05.400 PASS
09:30:05.700 FAIL
09:30:06.250 PASS
09:30:06.300 FAIL
09:30:06.400 PASS
Discussion
Loading comments…