3 ms·
This is an interesting approach to request rate limiting - the simplicity and lack of tuning is definitely appealing. Did you do anything to mitigate the scena
by twright0 10y ago
This is an interesting approach to request rate limiting - the simplicity and lack of tuning is definitely appealing.
Did you do anything to mitigate the scenario where multiple users are behind the same IP address? With this approach I would worry about locking out all users in a NAT when a single user misbehaves.
It's also scary to me to process something "last" - under high enough load you might never get back to the (potentially briefly) abusive user? Did you attempt to guarantee some minimum passthrough rate even for misbehaving users?
- Animats 10y agoAs with fair queuing in routers [1], you have to avoid infinite overtaking. If someone has have a request in progress, their other requests are stuck behind that one until the request in progress is serviced. Then your next request is eligible to be processed. [1] https://tools.ietf.org/html/rfc970 https://tools.ietf.org/html/rfc970