Should I apply rate limiting on Application level or use Nginx's feature?

Viewed 28

I'm trying to apply rate limit on my server and wondering whether I should use rate limiting libraries or use the Nginx's feature (the few lines of code)?

1 Answers

Both methods are valid that's why different famous frameworks like Laravel and NestJs have implementation for a rate limiter, but whether you want to apply rate limiting on application-level or web-server-level depends on your use case.

application-level rate limiting is more flexible and is best for when you are doing rate limiting based on a parameter specified in body of the request or a claim in the provided token e.g.

if user is a premium user
  limit user to x requests per y seconds
else
  limit user to x - m requests per y seconds

note: in this scenario, whether a user is a premium user must be decided either based on the claim in the token(token payload) i.e. JWT token that they provide with the request or querying database using a parameter they provide in some secure way.

another scenario is:

rate limit based on IP+email for login and register page
certain IP and email combination can only hit a route x times per y seconds

note: in this scenario, email is provided by user in the body of their request.

Although one web-server-level rate limiting benefit which comes to mind is that, you're application will be freed from the extra work which is caused by running the piece of code related to rate limit management for deciding which request must get rate limited. So it might be better for preventing DDOS attacks.

So all in all a combination of the two might be the best strategy in some cases.

Related