I'm trying to apply rate limit on my server and wondering whether I should use rate limiting libraries or use the Nginx's feature (the few lines of code)?
I'm trying to apply rate limit on my server and wondering whether I should use rate limiting libraries or use the Nginx's feature (the few lines of code)?
Both methods are valid that's why different famous frameworks like Laravel and NestJs have implementation for a rate limiter, but whether you want to apply rate limiting on application-level or web-server-level depends on your use case.
application-level rate limiting is more flexible and is best for when you are doing rate limiting based on a parameter specified in body of the request or a claim in the provided token e.g.
if user is a premium user
limit user to x requests per y seconds
else
limit user to x - m requests per y seconds
note: in this scenario, whether a user is a premium user must be decided either based on the claim in the token(token payload) i.e. JWT token that they provide with the request or querying database using a parameter they provide in some secure way.
another scenario is:
rate limit based on IP+email for login and register page
certain IP and email combination can only hit a route x times per y seconds
note: in this scenario, email is provided by user in the body of their request.
Although one web-server-level rate limiting benefit which comes to mind is that, you're application will be freed from the extra work which is caused by running the piece of code related to rate limit management for deciding which request must get rate limited. So it might be better for preventing DDOS attacks.
So all in all a combination of the two might be the best strategy in some cases.