Skip to content

IUserCodeRateLimiter Interface

Defines the contract for rate limiting user code verification attempts to prevent brute force attacks. RFC 8628 Section 5.1 recommends that the server rate-limit user code attempts. The word there is lowercase, so this is a mitigation the server chooses rather than one it inherits - and the choice is what makes the entropy argument in that section hold.

C#
public interface IUserCodeRateLimiter

Derived
↳ UserCodeRateLimiter

Methods

IUserCodeRateLimiter.CheckAsync(string, string) Method

Checks if a verification attempt should be allowed for the given user code and client identifier. Implements exponential backoff and per-IP rate limiting to prevent brute force attacks.

C#
System.Threading.Tasks.Task<Abblix.Utils.Result<bool,System.TimeSpan>> CheckAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code being verified.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<System.Boolean,System.TimeSpan>>
A Result<TSuccess,TFailure> containing: - Success (true): The verification attempt is allowed to proceed. - Failure (System.TimeSpan): The attempt is rate limited; the value indicates the duration the client must wait before retrying (Retry-After).

IUserCodeRateLimiter.RecordFailureAsync(string, string) Method

Records a failed verification attempt for rate limiting purposes.

C#
System.Threading.Tasks.Task RecordFailureAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code that failed verification.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task

IUserCodeRateLimiter.RecordSuccessAsync(string, string) Method

Records a successful verification to reset rate limiting counters.

C#
System.Threading.Tasks.Task RecordSuccessAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code that was successfully verified.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task