mirror of
https://github.com/samsonjs/rack-attack.git
synced 2026-04-27 15:07:41 +00:00
Acceptance test throttling with a dynamic period
This commit is contained in:
parent
e17d2d8974
commit
08b2cc4d95
1 changed files with 50 additions and 0 deletions
|
|
@ -62,4 +62,54 @@ describe "#throttle" do
|
||||||
get "/", {}, "REMOTE_ADDR" => "5.6.7.8", "X-APIKey" => "private-secret"
|
get "/", {}, "REMOTE_ADDR" => "5.6.7.8", "X-APIKey" => "private-secret"
|
||||||
assert_equal 429, last_response.status
|
assert_equal 429, last_response.status
|
||||||
end
|
end
|
||||||
|
|
||||||
|
it "supports period to be dynamic" do
|
||||||
|
# Could be used to have different rate limits for authorized
|
||||||
|
# vs general requests
|
||||||
|
period_proc = lambda do |request|
|
||||||
|
if request.get_header("X-APIKey") == "private-secret"
|
||||||
|
10
|
||||||
|
else
|
||||||
|
30
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
Rack::Attack.throttle("by ip", limit: 1, period: period_proc) do |request|
|
||||||
|
request.ip
|
||||||
|
end
|
||||||
|
|
||||||
|
# Using Time#at to align to start/end of periods exactly
|
||||||
|
# to achieve consistenty in different test runs
|
||||||
|
|
||||||
|
Timecop.travel(Time.at(0)) do
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "1.2.3.4"
|
||||||
|
assert_equal 200, last_response.status
|
||||||
|
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "1.2.3.4"
|
||||||
|
assert_equal 429, last_response.status
|
||||||
|
end
|
||||||
|
|
||||||
|
Timecop.travel(Time.at(10)) do
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "1.2.3.4"
|
||||||
|
assert_equal 429, last_response.status
|
||||||
|
end
|
||||||
|
|
||||||
|
Timecop.travel(Time.at(30)) do
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "1.2.3.4"
|
||||||
|
assert_equal 200, last_response.status
|
||||||
|
end
|
||||||
|
|
||||||
|
Timecop.travel(Time.at(0)) do
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "5.6.7.8", "X-APIKey" => "private-secret"
|
||||||
|
assert_equal 200, last_response.status
|
||||||
|
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "5.6.7.8", "X-APIKey" => "private-secret"
|
||||||
|
assert_equal 429, last_response.status
|
||||||
|
end
|
||||||
|
|
||||||
|
Timecop.travel(Time.at(10)) do
|
||||||
|
get "/", {}, "REMOTE_ADDR" => "5.6.7.8", "X-APIKey" => "private-secret"
|
||||||
|
assert_equal 200, last_response.status
|
||||||
|
end
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue