I found this in the recipes:
Rate limiting a route by current user (using Flask-Login):
@route("/test")
@login_required
@limiter.limit("1 per day", key_func = lambda : current_user.username)
def test_route():
return "42"
UPDATED: added simple example
Here is a simple Flask app implementing the recipe to give you better idea:
from flask import Flask, redirect
from flask_login import (
LoginManager,
UserMixin,
current_user,
login_required,
login_user,
logout_user
)
from flask_limiter import Limiter
app = Flask(__name__)
# flask-login
app.secret_key = 'super secret string'
login_manager = LoginManager()
login_manager.init_app(app)
# flask-limiter
limiter = Limiter(app)
# user class
class User(UserMixin):
def __init__(self, id):
self.id = id
self.username = id
# memory storage
users = [User('user')]
@login_manager.user_loader
def load_user(user_id):
return users[0]
@app.route('/')
def index():
return 'Hello, World!'
@app.route('/login')
def login():
if not current_user.is_authenticated:
login_user(users[0])
return redirect('/secured')
@app.route('/logout')
@login_required
def logout():
logout_user()
return redirect('/')
@app.route('/secured')
@login_required
@limiter.limit("2 per day", key_func = lambda : current_user.username)
def secured():
return f"Hello, {current_user.id}"
if __name__ == '__main__':
app.run()
Answer from Yohanes Gultom on Stack Overflow
» pip install Flask-Limiter
python - How can I rate-limit my Flask application per user? - Stack Overflow
How do I implement rate limiting?
Rate Limiting
Flask Rate Limiter does not seem compatible with Background Callbacks - any other options?
Videos
How do I implement rate limiting in my api? Would I have to use redis?
Basically I have an flask end point which is open to all (no user login required). I want to limit the access to the endpoint (e.g. 5 request/day). I want to throw an 429 error once the limit has reached.
Ideally, I would like to implement the same logic what medium.com uses to limit free readings to 3 per month.
I have read about Flask-Limitter (https://flask-limiter.readthedocs.io/en/stable/). The question I am having is will it make my application slow by keeping track of ips in memory?
Does anyone have any better examples/ideas with them?
TIA