{"_id":"@chetanb-11/express-redis-rate-limiter","_rev":"2-b4bc34d5fc128b99cb8dd803b168bf7b","name":"@chetanb-11/express-redis-rate-limiter","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@chetanb-11/express-redis-rate-limiter","version":"1.0.0","keywords":["express","rate-limit","redis","middleware","sliding-window","fixed-window"],"author":{"name":"Chetan"},"license":"ISC","_id":"@chetanb-11/express-redis-rate-limiter@1.0.0","maintainers":[{"name":"chetanb-11","email":"chetan6516@gmail.com"}],"homepage":"https://github.com/chetanb-11/Rate-Limiter#readme","bugs":{"url":"https://github.com/chetanb-11/Rate-Limiter/issues"},"dist":{"shasum":"f314ae164bc6cf1fed7e329d604407b2f340266b","tarball":"https://registry.npmjs.org/@chetanb-11/express-redis-rate-limiter/-/express-redis-rate-limiter-1.0.0.tgz","fileCount":33,"integrity":"sha512-+INW60XKi6beNRaoOfx631fFFYc8Rms+l5n0Hvl+DEeq1U+DvShIZ+Z4oJFHdGX1yHRyO6HPkIr3VVcIN+s9QA==","signatures":[{"sig":"MEYCIQC7dPoejqbRgYAh/y0nCRD4+MS8DCkBgoxyIobx7+XhZQIhAMDl9CchrQthZZHnL/ymLAZWkwyn9bS8lTyDw1Ioe7iJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":207307},"main":"index.js","type":"module","gitHead":"aaacd70e4c0f5267f2688ab760a45b097a1f1460","scripts":{"dev":"nodemon index.js","start":"node index.js"},"_npmUser":{"name":"chetanb-11","email":"chetan6516@gmail.com"},"repository":{"url":"git+https://github.com/chetanb-11/Rate-Limiter.git","type":"git"},"_npmVersion":"11.1.0","description":"A robust, route-specific distributed rate limiter for Express using Redis.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"ip":"^2.0.1","pino":"^10.3.1"},"_hasShrinkwrap":false,"devDependencies":{"cors":"^2.8.6","axios":"^1.15.0","dotenv":"^17.3.1","http-proxy-middleware":"^3.0.5"},"peerDependencies":{"redis":"^5.11.0","express":"^5.2.1"},"_npmOperationalInternal":{"tmp":"tmp/express-redis-rate-limiter_1.0.0_1779826621823_0.8760755814613284","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@chetanb-11/express-redis-rate-limiter","version":"1.0.1","description":"A robust, route-specific distributed rate limiter for Express using Redis.","main":"index.js","types":"index.d.ts","exports":{".":"./index.js"},"scripts":{"start":"node index.js","dev":"nodemon index.js"},"keywords":["express","rate-limit","redis","middleware","sliding-window","fixed-window"],"author":{"name":"Chetan"},"repository":{"type":"git","url":"git+https://github.com/chetanb-11/Rate-Limiter.git"},"license":"ISC","type":"module","dependencies":{"ip":"^2.0.1","pino":"^10.3.1"},"peerDependencies":{"express":">=4.0.0","redis":"^5.11.0"},"devDependencies":{"axios":"^1.15.0","cors":"^2.8.6","dotenv":"^17.3.1","http-proxy-middleware":"^3.0.5"},"_id":"@chetanb-11/express-redis-rate-limiter@1.0.1","gitHead":"9eb17248cc8d2a0f4cc356bc9d15bcb134e78b7e","bugs":{"url":"https://github.com/chetanb-11/Rate-Limiter/issues"},"homepage":"https://github.com/chetanb-11/Rate-Limiter#readme","_nodeVersion":"22.18.0","_npmVersion":"11.1.0","dist":{"integrity":"sha512-zDuFyGCyAI7FFIKsRZcW5ktaM7aCuvMYRsROvpoe08EmQHrf0RkUvM27McKychF+7GJ9i5dixbDqi0WZ1S3H1Q==","shasum":"418ab27de0448dbb77918431cee349d7c2a77a5e","tarball":"https://registry.npmjs.org/@chetanb-11/express-redis-rate-limiter/-/express-redis-rate-limiter-1.0.1.tgz","fileCount":9,"unpackedSize":14577,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIA6BuSbqEvjuYPKycvNH+AscLX9x/UgiqTC9QYf2L2+fAiBoC4thDr+UkM47+n25mtvH1ZkQzw1wWh65ENtfkZPASA=="}]},"_npmUser":{"name":"chetanb-11","email":"chetan6516@gmail.com"},"directories":{},"maintainers":[{"name":"chetanb-11","email":"chetan6516@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/express-redis-rate-limiter_1.0.1_1779898832549_0.9957080539443244"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-26T20:17:01.676Z","modified":"2026-05-27T16:20:32.832Z","1.0.0":"2026-05-26T20:17:01.973Z","1.0.1":"2026-05-27T16:20:32.746Z"},"bugs":{"url":"https://github.com/chetanb-11/Rate-Limiter/issues"},"author":{"name":"Chetan"},"license":"ISC","homepage":"https://github.com/chetanb-11/Rate-Limiter#readme","keywords":["express","rate-limit","redis","middleware","sliding-window","fixed-window"],"repository":{"type":"git","url":"git+https://github.com/chetanb-11/Rate-Limiter.git"},"description":"A robust, route-specific distributed rate limiter for Express using Redis.","maintainers":[{"name":"chetanb-11","email":"chetan6516@gmail.com"}],"readme":"# @chetanb-11/express-redis-rate-limiter\r\n\r\nA production-ready, distributed, route-specific rate-limiting middleware for **Express 5** (and v4) backed by **Redis**. Protect your APIs from abuse, manage traffic bursts, and prevent DDoS attacks with highly configurable limits and live monitoring.\r\n\r\n## 🚀 Features\r\n\r\n* **Dual Rate-Limiting Algorithms**: Ships with two battle-tested strategies:\r\n  * **Sliding Window Log**: Precise enforcement without edge-burst problems.\r\n  * **Fixed Window Counter**: High-throughput, O(1) memory usage.\r\n* **Route-Specific Limits**: Apply different thresholds to different endpoints seamlessly.\r\n* **Bring Your Own Redis**: Pass in your own Redis client instance (compatible with standard `redis` package).\r\n* **Fail-Open Design**: If the Redis connection drops, the middleware bypasses the rate limit and forwards traffic to ensure your API remains available.\r\n* **Live Stats Endpoint**: Includes a handy factory to generate an endpoint providing real-time Redis rate-limit metrics per IP and route.\r\n* **Standard HTTP Headers**: Automatically injects `X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Reset`, and `Retry-After`.\r\n\r\n---\r\n\r\n## 📦 Installation\r\n\r\n```bash\r\nnpm install @chetanb-11/express-redis-rate-limiter redis\r\n```\r\n\r\n> **Note**: `express` and `redis` are required as peer dependencies.\r\n\r\n---\r\n\r\n## 🚦 Quick Start\r\n\r\n```javascript\r\nimport express from 'express';\r\nimport { createClient } from 'redis';\r\nimport { createRateLimiter, createRateStats } from '@chetanb-11/express-redis-rate-limiter';\r\n\r\nconst app = express();\r\n\r\n// 1. Setup Redis Client\r\nconst redisClient = createClient({ url: 'redis://localhost:6379' });\r\n\r\nredisClient.on('error', (err) => console.log('Redis Client Error', err));\r\nawait redisClient.connect();\r\n\r\n// Trust proxy is required if you are behind a reverse proxy/load balancer (e.g., Nginx, Heroku, AWS)\r\napp.set('trust proxy', 1);\r\n\r\n// 2. Strict Rate Limiting for Secure Routes (10 requests per 60 seconds)\r\nconst strictLimiter = createRateLimiter({\r\n    redisClient,\r\n    strategy: 'sliding', // or 'fixed'\r\n    maxReq: 10,\r\n    timeWindow: 60 // in seconds\r\n});\r\n\r\napp.use('/api/secure', strictLimiter);\r\n\r\n// 3. Generous Rate Limiting for Public Routes (100 requests per 60 seconds)\r\nconst publicLimiter = createRateLimiter({\r\n    redisClient,\r\n    strategy: 'fixed',\r\n    maxReq: 100,\r\n    timeWindow: 60\r\n});\r\n\r\napp.use('/api/public', publicLimiter);\r\n\r\n// 4. Expose Live Rate Limiting Stats (Optional)\r\napp.get('/api/stats', createRateStats(redisClient));\r\n\r\n// Example Route\r\napp.get('/api/public/data', (req, res) => {\r\n    res.json({ message: \"Success!\" });\r\n});\r\n\r\napp.listen(3000, () => console.log('Server running on port 3000'));\r\n```\r\n\r\n---\r\n\r\n## 🛠️ API Reference\r\n\r\n### `createRateLimiter(options)`\r\n\r\nCreates an Express middleware function that rate-limits incoming requests.\r\n\r\n| Property | Type | Default | Description |\r\n|---|---|---|---|\r\n| `redisClient` | `RedisClient` | **Required** | An active Node.js Redis client instance. |\r\n| `strategy` | `String` | `'sliding'` | The algorithm to use: `'sliding'` or `'fixed'`. |\r\n| `maxReq` | `Number` | **Required** | Maximum number of allowed requests within the time window. |\r\n| `timeWindow` | `Number` | **Required** | The time window duration in seconds. |\r\n\r\n### `createRateStats(redisClient)`\r\n\r\nCreates an Express route handler `(req, res)` that returns live metrics of all active rate limits stored in Redis. Useful for internal dashboards or monitoring.\r\n\r\n**Response Example:**\r\n```json\r\n{\r\n  \"total\": 1,\r\n  \"stats\": [\r\n    {\r\n      \"ip\": \"127.0.0.1\",\r\n      \"route\": \"/api/secure\",\r\n      \"strategy\": \"sliding\",\r\n      \"requests\": 5,\r\n      \"ttl\": 45\r\n    }\r\n  ]\r\n}\r\n```\r\n\r\n---\r\n\r\n## 📊 Response Headers\r\n\r\nEvery proxied request includes rate-limit metadata attached to the response headers:\r\n\r\n```http\r\nX-RateLimit-Limit: 10\r\nX-RateLimit-Remaining: 7\r\nX-RateLimit-Reset: 60\r\n```\r\n\r\nWhen a client exceeds the limit, the middleware intercepts the request and responds with a `429 Too Many Requests` status, along with:\r\n\r\n```json\r\nHTTP/1.1 429 Too Many Requests\r\nRetry-After: 60\r\n\r\n{\r\n  \"error\": \"Too Many Requests\",\r\n  \"message\": \"Limit of 10 requests per 60s exceeded\",\r\n  \"retryAfter\": 60\r\n}\r\n```\r\n\r\n---\r\n\r\n## 🤝 Contributing\r\n\r\nContributions, issues, and feature requests are welcome! Feel free to check the [issues page](https://github.com/chetanb-11/Rate-Limiter/issues).\r\n\r\n## 📄 License\r\n\r\nThis project is licensed under the ISC License.","readmeFilename":"README.md"}