Перейти к содержимому
Эта страница ещё не переведена.

IUserCodeRateLimiter Interface

Defines the contract for rate limiting user code verification attempts to prevent brute force attacks. RFC 8628 Section 5.1 recommends that the server rate-limit user code attempts. The word there is lowercase, so this is a mitigation the server chooses rather than one it inherits - and the choice is what makes the entropy argument in that section hold.

C#
public interface IUserCodeRateLimiter

Derived
↳ UserCodeRateLimiter

Methods

IUserCodeRateLimiter.CheckAsync(string, string) Method

Checks if a verification attempt should be allowed for the given user code and client identifier. Implements exponential backoff and per-IP rate limiting to prevent brute force attacks.

C#
System.Threading.Tasks.Task<Abblix.Utils.Result<bool,System.TimeSpan>> CheckAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code being verified.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task<Abblix.Utils.Result<System.Boolean,System.TimeSpan>>
A Result<TSuccess,TFailure> containing: - Success (true): The verification attempt is allowed to proceed. - Failure (System.TimeSpan): The attempt is rate limited; the value indicates the duration the client must wait before retrying (Retry-After).

IUserCodeRateLimiter.RecordFailureAsync(string, string) Method

Records a failed verification attempt for rate limiting purposes.

C#
System.Threading.Tasks.Task RecordFailureAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code that failed verification.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task

IUserCodeRateLimiter.RecordSuccessAsync(string, string) Method

Records a successful verification to reset rate limiting counters.

C#
System.Threading.Tasks.Task RecordSuccessAsync(string userCode, string clientIdentifier);

Parameters

userCode System.String

The user code that was successfully verified.

clientIdentifier System.String

The client identifier (IP address or other identifier).

Returns

System.Threading.Tasks.Task