WebSvc.RateLimitAdmin
1.1.0
dotnet add package WebSvc.RateLimitAdmin --version 1.1.0
NuGet\Install-Package WebSvc.RateLimitAdmin -Version 1.1.0
<PackageReference Include="WebSvc.RateLimitAdmin" Version="1.1.0" />
<PackageVersion Include="WebSvc.RateLimitAdmin" Version="1.1.0" />
<PackageReference Include="WebSvc.RateLimitAdmin" />
paket add WebSvc.RateLimitAdmin --version 1.1.0
#r "nuget: WebSvc.RateLimitAdmin, 1.1.0"
#:package WebSvc.RateLimitAdmin@1.1.0
#addin nuget:?package=WebSvc.RateLimitAdmin&version=1.1.0
#tool nuget:?package=WebSvc.RateLimitAdmin&version=1.1.0
WebSvc.RateLimitAdmin
Standalone rate-limiting admin UI for CrudApi-based platforms.
- Guards all CRUD traffic per database, scoped per credential (API key, Basic Auth, or JWT) via
{AuthType}:{SubjectId}— a JWT holder gets the same protection as an API-key holder. - Own SQLite/MySQL storage (
Scripts/) — no dependency onWebSvc.CrudAdmin's assembly. - Independent login at
/ratelimitadmin/login, plus a signed, short-lived, single-use auto-login handoff from apps you're already signed into (CrudAdmin's Databases page, the Tenant Portal). - Global Admin view (all tenants/databases) and Tenant Admin view (own databases only) — a Global Admin sets a per-tenant ceiling; the tenant tunes their own databases freely underneath it.
- A database's limit row is created automatically (enabled, default ceiling) the first time real traffic is seen for it — nothing to provision ahead of time.
- Fails open if the counter store is unreachable — protection is a bonus layer, never a gate the platform depends on staying up.
- A retention job purges old usage history on a UI-configurable schedule
(
usage.retention_days, default 30).
Setup
builder.Services.AddRateLimitAdmin(builder.Configuration);
// ...
app.UseRateLimitAdmin();
// ...
app.MapRateLimitAdmin();
Configuration (appsettings.json, section RateLimitAdmin): RootPath (default
/ratelimitadmin), DbEngine (Sqlite default, or MySql — also settable via
RATELIMITADMIN_DB_ENGINE/RATELIMITADMIN_MYSQL_CONNECTION_STRING env vars, mirroring
CrudAdmin's own convention), ConnectionString, DataDirectory (default RateLimitData/ under
the app's base directory — deliberately separate from CrudAdmin's Data/ folder; mount/persist
it separately in any container deployment), Username/PasswordHash (the Global-Admin
break-glass manual-login credential — tenant admins only ever arrive via the signed handoff, so
there's no per-tenant account to provision), SessionHours, DefaultRequestsPerMinute (300).
To bridge caller identity from CrudAdmin (so the traffic gate knows who's calling) and to enable
the auto-login handoff, also call AddCrudAdmin(...) in the same host:
- RateLimitAdmin reads a small set of well-known
ctx.Itemsstring keys (CrudAdmin.Identity.AuthType/SubjectId/TenantId/DatabaseKey) that CrudAdmin'sCrudAuthMiddlewarestamps after a successful authentication — no compiled dependency either direction, just a documented naming convention. - RateLimitAdmin injects whatever
IDataProtectionProvideris already registered (CrudAdmin'sAddCrudAdmin()configures one, persisted to disk) rather than configuring its own, so the two packages share a key ring automatically with zero extra wiring.
Deliberately out of scope for v1
The design leaves room for these; the code doesn't implement them yet:
- Redis-backed counter store —
ICounterStoreis a small interface (SqlCounterStoreis the default,MemoryCounterStoreis single-instance/dev-only); aRedisCounterStorecan be added without touching the rest of the package, and would ship as a separate companion package so the core never takes a hard Redis dependency. requests_per_hourenforcement — the schema column exists (ratelimit_database_limits,ratelimit_tenant_ceilings); only the per-minute fixed window is actually checked today.
Versions
- 1.0.0 — initial release.
© Narender Kumar
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Microsoft.Data.Sqlite (>= 8.0.0)
- MySqlConnector (>= 2.6.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.