{"_id":"@alkihis/express-rate-limit","_rev":"4-316ab167b23197277d2f7897f8bcb803","name":"@alkihis/express-rate-limit","dist-tags":{"latest":"5.1.6"},"versions":{"5.1.3":{"name":"@alkihis/express-rate-limit","version":"5.1.3","description":"Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.","homepage":"https://github.com/alkihis/express-rate-limit","author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"repository":{"type":"git","url":"git+https://github.com/nfriedly/express-rate-limit.git"},"license":"MIT","main":"lib/express-rate-limit.js","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"dependencies":{"@types/node":"^14.0.5"},"devDependencies":{"@types/express":"^4.17.6","eslint":"^6.8.0","eslint-config-prettier":"^6.10.1","eslint-plugin-prettier":"^3.1.2","express":"^4.17.1","husky":"^4.2.3","mocha":"^7.1.1","prettier":"^2.0.4","pretty-quick":"^2.0.1","supertest":"^4.0.2"},"scripts":{"lint":"eslint .","autofix":"npm run lint -- --fix","test":"npm run lint && mocha","precommit":"pretty-quick --staged"},"gitHead":"d82df0b1fec345e88382b63bbe03f6ee672ccc96","bugs":{"url":"https://github.com/nfriedly/express-rate-limit/issues"},"_id":"@alkihis/express-rate-limit@5.1.3","_nodeVersion":"14.3.0","_npmVersion":"6.14.5","dist":{"integrity":"sha512-IanTszDzUPRBatPsM45/nMs4UqFPtpLo8//nhLhGFQy+p16Hcd7T2terRRbkxDRjKeb+6RuShjHKgfwFF2YPdg==","shasum":"e69486ee9cfb3d687526519facdcd5b0a37d5b47","tarball":"https://registry.npmjs.org/@alkihis/express-rate-limit/-/express-rate-limit-5.1.3.tgz","fileCount":9,"unpackedSize":25256,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJezlTmCRA9TVsSAnZWagAA1+wP/AkfYselIqj+7kWBrnKg\nEGvOe51UJFys27w182L1iaOP6L2HOV6grpXLvbl3QJRPm/W5xCOPn5Y9POuR\n2+mFvMHPXAiKKVnDilNll9QbO0jt+1jyGs8nl4WzzjtEzFhFAbueBcysl1CB\nlCVtgtaEwqhCtrwX8DpiGRQ+LPExnPmteAv1P/GTH8LpC5ZREkg+umQt91R3\nI43t5DbehClNaVw0zVHhht2KpRHPBw5e0dkqjVNveVnYak7ksGvdGLvPY2yK\ngWj4ZcCwMBcpGlbZKsBDqkEdFK5mFVygGkTV+F+HLClTolU93RczvIE15FYV\nzJqR9qVecqr4eVUog7+hoAMwMyFUbOx158BiOhsWOb04O81i1zVLARMjDcZ0\n3GsqKJy5R3IY67poggwZFz5dcVjmSonJ1ge2zKbxiMZ++koLsFSkSAG+U+8f\naxVaHlvB1NiLVHCyuVKxS9gifylg56NT3hMMQvuylzvwDKQ+mPrY55TPaIE5\nVF/kgmBxK9CwqhnARtK9CQJ538aCS2nWK2UvD/xHpt+IVa5ra0u22sgJF43G\nqN4jNvE5WE1+BmRBkxIRUMokSdmjhSFoKUaI1SWaPr6CA8aTHco0/H1RCil1\nfoSjUq03ame05hl9ghgC5lXHUnXCVgBE8rATNjNjFfPFjiaKypq4Aa8zJW8L\n7SRN\r\n=V+Cv\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIARf/oyPC1dkXB41dFu/K3R3qK8X/ehV7RBEJxpydXMYAiBUq+u+TLnsWP66s6FbmtFWJqKCEh0Q4TYbZRXzX0aCFg=="}]},"maintainers":[{"name":"alkihis","email":"tulouca@gmail.com"}],"_npmUser":{"name":"alkihis","email":"tulouca@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-rate-limit_5.1.3_1590580454445_0.43984214723475445"},"_hasShrinkwrap":false},"5.1.4":{"name":"@alkihis/express-rate-limit","version":"5.1.4","description":"Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.","homepage":"https://github.com/alkihis/express-rate-limit","author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"repository":{"type":"git","url":"git+https://github.com/nfriedly/express-rate-limit.git"},"license":"MIT","main":"lib/express-rate-limit.js","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"dependencies":{"@types/node":"^14.0.5"},"devDependencies":{"@types/express":"^4.17.6","eslint":"^6.8.0","eslint-config-prettier":"^6.10.1","eslint-plugin-prettier":"^3.1.2","express":"^4.17.1","husky":"^4.2.3","mocha":"^7.1.1","prettier":"^2.0.4","pretty-quick":"^2.0.1","supertest":"^4.0.2"},"scripts":{"lint":"eslint .","autofix":"npm run lint -- --fix","test":"npm run lint && mocha","precommit":"pretty-quick --staged"},"gitHead":"929c191730ea8c4e8003d12145a860d3bab05a13","bugs":{"url":"https://github.com/nfriedly/express-rate-limit/issues"},"_id":"@alkihis/express-rate-limit@5.1.4","_nodeVersion":"14.3.0","_npmVersion":"6.14.5","dist":{"integrity":"sha512-HPigXk7p8TfbAHR0ay/SNW/MHtKOSAAD62M8+b3/nUzicvUmpZ/9cvvYD5EDycOvez4kLHpDzRCKmyCkE9ymsg==","shasum":"79b6a697299bf041716519efbaaa046452737718","tarball":"https://registry.npmjs.org/@alkihis/express-rate-limit/-/express-rate-limit-5.1.4.tgz","fileCount":9,"unpackedSize":25283,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJezlVXCRA9TVsSAnZWagAAGxsQAJ3ldwwd0MYgKgTHJ1LK\na3FCWblzoaZm5wjPeMO63WW7V08hzTef0LqE64eiVZLaQ26xPZ9UpZ2TANYY\nGd/tRO5Pa/IiJlK1VHNf2lkz+NR58vaXTt2we9spRDzk61wzHkvMsG+RWLya\n/2/ISZAj+KHoo8zBjafrZsAUAjIGD3u1ClixKBbBv/5BGAwDkwa9zW4FXmKP\nbkTNpxVpgp+ydZ+/tma+vIz+gMAQ2QzC0cX2KhUAQKzw+5Mxj6CKcZbc9wae\n39UoWrybot/xmXTyYsDHZGcvMc/Wn9PrWHII118JQNenJZkUwMjQL7wchuW+\nTjWNxC+V9ieVXroLaQbbWg+liY2ljOMo5DWGJCu1hHyCC20LtytAr2RJg+rJ\nrEj4LbLarcfmZge8IfxYyvi/7OF4MVF/MDuhqeygkBo5UTTKISxM/pVy5Cri\n4CO7wiyweEWoDff+HvJ6aZ/Us9cNaknkBVRsJ+Nq7Y0qGoTCe98CQvmEb2Wo\nfOZA69hWcnWmsYR2CLlwdUj8jeSzbvQCEVKnr3f6yxKVVDnBho3N8NePXyIz\nP8fL0NOaekbkEwC6LW8t/LHwBSi2f5joqLu7TmeUwAuu6Hb6vUKYX4WNCnlD\nYF0nJaUGo0XivSyxHwuLUh3/ajwcX1dthM+FuJZQj/GnyUV0IXFU1ovj5kWb\n3ARM\r\n=omI7\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDZd8W3n8qXu1lN9yXAes+LxuT7ltc1cGObGyQtjgwpxwIgQdfML65ekyiTDnZ8SkDjnAPintssqvqgK5cFJ3yOe6k="}]},"maintainers":[{"name":"alkihis","email":"tulouca@gmail.com"}],"_npmUser":{"name":"alkihis","email":"tulouca@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-rate-limit_5.1.4_1590580566563_0.8797458198967183"},"_hasShrinkwrap":false},"5.1.5":{"name":"@alkihis/express-rate-limit","version":"5.1.5","description":"Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.","homepage":"https://github.com/alkihis/express-rate-limit","author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"repository":{"type":"git","url":"git+https://github.com/nfriedly/express-rate-limit.git"},"license":"MIT","main":"lib/express-rate-limit.js","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"dependencies":{"@types/node":"^14.0.5"},"devDependencies":{"@types/express":"^4.17.6","eslint":"^6.8.0","eslint-config-prettier":"^6.10.1","eslint-plugin-prettier":"^3.1.2","express":"^4.17.1","husky":"^4.2.3","mocha":"^7.1.1","prettier":"^2.0.4","pretty-quick":"^2.0.1","supertest":"^4.0.2"},"scripts":{"lint":"eslint .","autofix":"npm run lint -- --fix","test":"npm run lint && mocha","precommit":"pretty-quick --staged"},"gitHead":"8d5c945bde5f615d6fc554e85222979a67f5d377","bugs":{"url":"https://github.com/nfriedly/express-rate-limit/issues"},"_id":"@alkihis/express-rate-limit@5.1.5","_nodeVersion":"14.5.0","_npmVersion":"6.14.6","dist":{"integrity":"sha512-G6ve1xfd/akFPX7wyrAAvPSNiAyMgkRDqQGWKguekkLIp4ijP9uT/bJC1pjok80eTGwazcN7DePG3Tr6zOvPIA==","shasum":"2f8145eea1a0503edce51b7641d3d67e59a70a36","tarball":"https://registry.npmjs.org/@alkihis/express-rate-limit/-/express-rate-limit-5.1.5.tgz","fileCount":9,"unpackedSize":25327,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfIEfuCRA9TVsSAnZWagAA5MAQAIVy/0l+JmQxwco0pHsc\nsIjPwW6xAtRZjpBrMzi/kNRFQ+5amdrOaJAgL/TmLIz5CIgqS2p3bHZ9255b\n9CEFa7VG7FL0cvCNKoTld/TAyuTWRJhfhJT75B6bEyTctEc0Ial+jciB+8Vu\nZ04necBWpMEYalAmScpLtP61ZXFFXX+ZGADZ1vjrrkvCgjtuoStBKELA+Lkv\nkPZbp8to6Q88CRGOBs7QNi68krp3ByrNXbrobed4Rgb+tKUO3uzTP1b7inL5\nZ1PNNLmF7xRObQuhc3sd124JNhMLILIU50HvZ7u1I3jBSvHf/f85kyLMD2lA\nU4Wn2HbzQHElL0Nn1ARdHyY4Jas+3OO+E/XfXC+hOC/VUaiqTl7vg7wZOnGX\nIxwH6Ksfb8JOSI46P4pV2EJt5HBhHicS+klWVFS9KtrCsRYgXiP6wnVfQvJs\n/7yTQZTG42CAFvOGnCUvqruzMTRc6xMuB26JxMH1S+xsrL8pgMC5W1M9ajOc\nzvvRKDVZJxKVdwuF0V4m8mhxywgzyzeRXz70ZXc7lAAL+Kvdo7jiwL7mabv6\nNJzLPMEf/8xlfkGGqnGg+Ua49n19XJrtEMNwZfrS+GEQX+gE/Vx+gKO17ni3\nprRKgTePLJyg53kD9aYcJ/T8ZQOAhSVepvyqY3TKNkoYYyjxn58dUNBF4SXr\nFA2D\r\n=pvPv\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD4ZMnIElG3gjtoIeR8yb8Swf3xBlMHdMj6Dx2xDSwSfAIgXni4ZvCOZxbSaK5QX14lTP20sMqM627GgAtjwGsJFaw="}]},"maintainers":[{"name":"alkihis","email":"tulouca@gmail.com"}],"_npmUser":{"name":"alkihis","email":"tulouca@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-rate-limit_5.1.5_1595951080974_0.9634017583356831"},"_hasShrinkwrap":false},"5.1.6":{"name":"@alkihis/express-rate-limit","version":"5.1.6","description":"Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.","homepage":"https://github.com/alkihis/express-rate-limit","author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"repository":{"type":"git","url":"git+https://github.com/nfriedly/express-rate-limit.git"},"license":"MIT","main":"lib/express-rate-limit.js","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"dependencies":{"@types/node":"^14.0.5"},"devDependencies":{"@types/express":"^4.17.6","eslint":"^6.8.0","eslint-config-prettier":"^6.10.1","eslint-plugin-prettier":"^3.1.2","express":"^4.17.1","husky":"^4.2.3","mocha":"^7.1.1","prettier":"^2.0.4","pretty-quick":"^2.0.1","supertest":"^4.0.2"},"scripts":{"lint":"eslint .","autofix":"npm run lint -- --fix","test":"npm run lint && mocha","precommit":"pretty-quick --staged"},"gitHead":"11c93d7090ffd5fa66f046784a39cd4ce77786b9","bugs":{"url":"https://github.com/nfriedly/express-rate-limit/issues"},"_id":"@alkihis/express-rate-limit@5.1.6","_nodeVersion":"14.5.0","_npmVersion":"6.14.6","dist":{"integrity":"sha512-VIwI6XjvGwnuHQgo4QHb8usLJTEb1sXBGt8FFj8zQrhwsFnXbaV6vPJBgw2CEVc29Php3mh2kU6+bXu9jK1J7w==","shasum":"cf918198236dbaaefeeec8517a49084ed45659d4","tarball":"https://registry.npmjs.org/@alkihis/express-rate-limit/-/express-rate-limit-5.1.6.tgz","fileCount":9,"unpackedSize":25294,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJfIEhiCRA9TVsSAnZWagAAo/AP/i+oyTwpKCs0xAj6hueS\nKF8yxEb4HsIK4R0dDwQ10BaqmtFLXGSkHnpYiBH6Nzu0YaHjyw1JlzVFsmO0\nayD9QADrw8LVffvQTxaLHLzPxo+dU2U4mcverNYeE/m7zfcqllMHgi+i6brf\nDRY1+WziYTMRB2qyun5MLNJfT8GsThWeWpJSowikvXGjZf0RBRZjMLNZ2WKX\nZUeDH+zJ3rIK12DGmJroOCsVcQSAk81mCZ359wTUmFGRVT3jxNytt1EULOZ5\npUaPtKWIHjIAdefpev8gt19QmtAp9a6sWIZ1Rc9HDsafk9K0C5Usz60ZH1ya\nw1b2Z8O+s/zHxiL483ZaN+axLExI9EWuz4FNLNN25PFyEbI9cwZ3e03BapxH\nof8d8q4BdwEUj1lraNjAqNjUPoKa9gqeHVVFvvEoP2C8KExY69skz/t6Bz/l\nhSdXK9TkycowEajvRFPBvxpzf0XCconcLHht86yAIFT1R9kEKV0VmRMwB0hm\nQU04ku25/WSNzJIcWYnmsRRBG0qYKOFvaAtY9D7RumSpg3JYu9waTXHWw/x4\nZVsKpp9xWd/bDEO/ZkUcTHN8T7Fl9HJQS09J4zgU+npOQRpkjHPQFInDzMws\ny+685m8dg19udikIb3kmdJt8mgZKhAyhL6EPnLdRDhym8QIqk4eifND+sFs6\n6ieY\r\n=fPdC\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHOkmn4WBpB13cwD7ntBYnHdP43RNosyfMOiRXBAM9Q6AiEAzmZDlXFmRhWxCHHIiYYbco+9ZnaBMvHFxDsnoPVLSIM="}]},"maintainers":[{"name":"alkihis","email":"tulouca@gmail.com"}],"_npmUser":{"name":"alkihis","email":"tulouca@gmail.com"},"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/express-rate-limit_5.1.6_1595951202496_0.2550930902516946"},"_hasShrinkwrap":false}},"time":{"created":"2020-05-27T11:54:14.302Z","5.1.3":"2020-05-27T11:54:14.553Z","modified":"2022-04-04T13:31:08.920Z","5.1.4":"2020-05-27T11:56:06.729Z","5.1.5":"2020-07-28T15:44:41.072Z","5.1.6":"2020-07-28T15:46:42.600Z"},"maintainers":[{"name":"alkihis","email":"tulouca@gmail.com"}],"description":"Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.","homepage":"https://github.com/alkihis/express-rate-limit","keywords":["express-rate-limit","express","rate","limit","ratelimit","rate-limit","middleware","ip","auth","authorization","security","brute","force","bruteforce","brute-force","attack"],"repository":{"type":"git","url":"git+https://github.com/nfriedly/express-rate-limit.git"},"author":{"name":"Nathan Friedly","url":"http://nfriedly.com/"},"bugs":{"url":"https://github.com/nfriedly/express-rate-limit/issues"},"license":"MIT","readme":"# Express Rate Limit\n\n[![Build Status](https://secure.travis-ci.org/nfriedly/express-rate-limit.png?branch=master)](http://travis-ci.org/nfriedly/express-rate-limit)\n[![NPM version](http://badge.fury.io/js/express-rate-limit.png)](https://npmjs.org/package/express-rate-limit \"View this project on NPM\")\n[![Dependency Status](https://david-dm.org/nfriedly/express-rate-limit.png?theme=shields.io)](https://david-dm.org/nfriedly/express-rate-limit)\n[![Development Dependency Status](https://david-dm.org/nfriedly/express-rate-limit/dev-status.png?theme=shields.io)](https://david-dm.org/nfriedly/express-rate-limit#info=devDependencies)\n\nBasic rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.\n\nPlays nice with [express-slow-down](https://www.npmjs.com/package/express-slow-down).\n\nNote: this module does not share state with other processes/servers by default.\nIf you need a more robust solution, I recommend using an external store:\n\n### Stores\n\n- Memory Store _(default, built-in)_ - stores hits in-memory in the Node.js process. Does not share state with other servers or processes.\n- [Redis Store](https://npmjs.com/package/rate-limit-redis)\n- [Memcached Store](https://npmjs.org/package/rate-limit-memcached)\n- [Mongo Store](https://www.npmjs.com/package/rate-limit-mongo)\n\n### Alternate Rate-limiters\n\nThis module was designed to only handle the basics and didn't even support external stores initially. These other options all are excellent pieces of software and may be more appropriate for some situations:\n\n- [rate-limiter-flexible](https://www.npmjs.com/package/rate-limiter-flexible)\n- [express-brute](https://www.npmjs.com/package/express-brute)\n- [rate-limiter](https://www.npmjs.com/package/express-limiter)\n\n## Install\n\n```sh\n$ npm install --save express-rate-limit\n```\n\n## Usage\n\nFor an API-only server where the rate-limiter should be applied to all requests:\n\n```js\nconst rateLimit = require(\"express-rate-limit\");\n\n// Enable if you're behind a reverse proxy (Heroku, Bluemix, AWS ELB, Nginx, etc)\n// see https://expressjs.com/en/guide/behind-proxies.html\n// app.set('trust proxy', 1);\n\nconst limiter = rateLimit({\n  windowMs: 15 * 60 * 1000, // 15 minutes\n  max: 100 // limit each IP to 100 requests per windowMs\n});\n\n//  apply to all requests\napp.use(limiter);\n```\n\nFor a \"regular\" web server (e.g. anything that uses `express.static()`), where the rate-limiter should only apply to certain requests:\n\n```js\nconst rateLimit = require(\"express-rate-limit\");\n\n// Enable if you're behind a reverse proxy (Heroku, Bluemix, AWS ELB, Nginx, etc)\n// see https://expressjs.com/en/guide/behind-proxies.html\n// app.set('trust proxy', 1);\n\nconst apiLimiter = rateLimit({\n  windowMs: 15 * 60 * 1000, // 15 minutes\n  max: 100\n});\n\n// only apply to requests that begin with /api/\napp.use(\"/api/\", apiLimiter);\n```\n\nCreate multiple instances to apply different rules to different routes:\n\n```js\nconst rateLimit = require(\"express-rate-limit\");\n\n// Enable if you're behind a reverse proxy (Heroku, Bluemix, AWS ELB, Nginx, etc)\n// see https://expressjs.com/en/guide/behind-proxies.html\n// app.set('trust proxy', 1);\n\nconst apiLimiter = rateLimit({\n  windowMs: 15 * 60 * 1000, // 15 minutes\n  max: 100\n});\napp.use(\"/api/\", apiLimiter);\n\nconst createAccountLimiter = rateLimit({\n  windowMs: 60 * 60 * 1000, // 1 hour window\n  max: 5, // start blocking after 5 requests\n  message:\n    \"Too many accounts created from this IP, please try again after an hour\"\n});\napp.post(\"/create-account\", createAccountLimiter, function(req, res) {\n  //...\n});\n```\n\n**Note:** most stores will require additional configuration, such as custom prefixes, when using multiple instances. The default built-in memory store is an exception to this rule.\n\n## Request API\n\nA `req.rateLimit` property is added to all requests with the `limit`, `current`, and `remaining` number of requests and, if the store provides it, a `resetTime` Date object. These may be used in your application code to take additional actions or inform the user of their status.\n\n## Configuration options\n\n### max\n\nMax number of connections during `windowMs` milliseconds before sending a 429 response.\n\nMay be a number, or a function that returns a number or a promise. If `max` is a function, it will be called with `req` and `res` params.\n\nDefaults to `5`. Set to `0` to disable.\n\n### windowMs\n\nTimeframe for which requests are checked/remembered. Also used in the Retry-After header when the limit is reached.\n\nNote: with non-default stores, you may need to configure this value twice, once here and once on the store. In some cases the units also differ (e.g. seconds vs miliseconds)\n\nDefaults to `60000` (1 minute).\n\n### message\n\nError message sent to user when `max` is exceeded.\n\nMay be a String, JSON object, or any other value that Express's [res.send](https://expressjs.com/en/4x/api.html#res.send) supports.\n\nDefaults to `'Too many requests, please try again later.'`\n\n### statusCode\n\nHTTP status code returned when `max` is exceeded.\n\nDefaults to `429`.\n\n### headers\n\nEnable headers for request limit (`X-RateLimit-Limit`) and current usage (`X-RateLimit-Remaining`) on all responses and time to wait before retrying (`Retry-After`) when `max` is exceeded.\n\nDefaults to `true`. Behavior may change in the next major release.\n\n### draft_polli_ratelimit_headers\n\nEnable headers conforming to the [ratelimit standardization proposal](https://tools.ietf.org/id/draft-polli-ratelimit-headers-01.html): `RateLimit-Limit`, `RateLimit-Remaining`, and, if the store supports it, `RateLimit-Reset`. May be used in conjunction with, or instead of the `headers` option.\n\nDefaults to `false`. Behavior and name will likely change in future releases.\n\n### keyGenerator\n\nFunction used to generate keys.\n\nDefaults to req.ip:\n\n```js\nfunction (req /*, res*/) {\n    return req.ip;\n}\n```\n\n### handler\n\nThe function to handle requests once the max limit is exceeded. It receives the request and the response objects. The \"next\" param is available if you need to pass to the next middleware.\n\nThe`req.rateLimit` object has `limit`, `current`, and `remaining` number of requests and, if the store provides it, a `resetTime` Date object.\n\nDefaults to:\n\n```js\nfunction (req, res, /*next*/) {\n    res.status(options.statusCode).send(options.message);\n}\n```\n\n### onLimitReached\n\nFunction that is called the first time a user hits the rate limit within a given window.\n\nThe`req.rateLimit` object has `limit`, `current`, and `remaining` number of requests and, if the store provides it, a `resetTime` Date object.\n\nDefault is an empty function:\n\n```js\nfunction (req, res, options) {\n  /* empty */\n}\n```\n\n### skipFailedRequests\n\nWhen set to `true`, failed requests won't be counted. Request considered failed when:\n\n- response status >= 400\n- requests that were cancelled before last chunk of data was sent (response `close` event triggered)\n- response `error` event was triggrered by response\n\n(Technically they are counted and then un-counted, so a large number of slow requests all at once could still trigger a rate-limit. This may be fixed in a future release.)\n\nDefaults to `false`.\n\n### skipSuccessfulRequests\n\nWhen set to `true` successful requests (response status < 400) won't be counted.\n(Technically they are counted and then un-counted, so a large number of slow requests all at once could still trigger a rate-limit. This may be fixed in a future release.)\n\nDefaults to `false`.\n\n### skip\n\nFunction used to skip (whitelist) requests. Returning `true` from the function will skip limiting for that request.\n\nDefaults to always `false` (count all requests):\n\n```js\nfunction (/*req, res*/) {\n    return false;\n}\n```\n\n### store\n\nThe storage to use when persisting rate limit attempts.\n\nBy default, the [MemoryStore](lib/memory-store.js) is used.\n\nAvailable data stores are:\n\n- MemoryStore: _(default)_ Simple in-memory option. Does not share state when app has multiple processes or servers.\n- [rate-limit-redis](https://npmjs.com/package/rate-limit-redis): A [Redis](http://redis.io/)-backed store, more suitable for large or demanding deployments.\n- [rate-limit-memcached](https://npmjs.org/package/rate-limit-memcached): A [Memcached](https://memcached.org/)-backed store.\n- [rate-limit-mongo](https://www.npmjs.com/package/rate-limit-mongo): A [MongoDB](https://www.mongodb.com/)-backed store.\n\nYou may also create your own store. It must implement the following in order to function:\n\n```js\nfunction SomeStore() {\n  /**\n   * Increments the value in the underlying store for the given key.\n   * @method function\n   * @param {string} key - The key to use as the unique identifier passed\n   *                     down from RateLimit.\n   * @param {Function} cb - The callback issued when the underlying\n   *                                store is finished.\n   *\n   * The callback should be called with three values:\n   *  - error (usually null)\n   *  - hitCount for this IP\n   *  - resetTime - JS Date object (optional, but necessary for X-RateLimit-Reset header)\n   */\n  this.incr = function(key, cb) {\n    // increment storage\n    cb(null, hits, resetTime);\n  };\n\n  /**\n   * Decrements the value in the underlying store for the given key. Used only when skipFailedRequests is true\n   * @method function\n   * @param {string} key - The key to use as the unique identifier passed\n   *                     down from RateLimit.\n   */\n  this.decrement = function(key) {\n    // decrement storage\n  };\n\n  /**\n   * Resets a value with the given key.\n   * @method function\n   * @param  {[type]} key - The key to reset\n   */\n  this.resetKey = function(key) {\n    // remove key from storage or reset it to 0\n  };\n}\n```\n\n## Instance API\n\n### instance.resetKey(key)\n\nResets the rate limiting for a given key. (Allow users to complete a captcha or whatever to reset their rate limit, then call this method.)\n\n## Summary of breaking changes:\n\n### v5 changes\n\n- Removed index.d.ts. (See [#138](https://github.com/nfriedly/express-rate-limit/issues/138))\n\n### v4 Changes\n\n- Express Rate Limit no longer modifies the passed-in options object, it instead makes a clone of it.\n\n### v3 Changes\n\n- Removed `delayAfter` and `delayMs` options; they were moved to a new module: [express-slow-down](https://npmjs.org/package/express-slow-down).\n- Simplified the default `handler` function so that it no longer changes the response format. Now uses [res.send](https://expressjs.com/en/4x/api.html#res.send).\n- `onLimitReached` now only triggers once for a given ip and window. only `handle` is called for every blocked request.\n\n### v2 Changes\n\nv2 uses a less precise but less resource intensive method of tracking hits from a given IP. v2 also adds the `limiter.resetKey()` API and removes the `global: true` option.\n\n## License\n\nMIT © [Nathan Friedly](http://nfriedly.com/)\n","readmeFilename":"README.md"}