middleware.auth_rate_limit

Page actions AI-ready formats and sharing
Open LLM text
Share with AI
Ask Claude Ask ChatGPT Ask Gemini Ask Copilot

Keyed rate limiting middleware.

Provides a small in-memory limiter intended for authentication endpoints like login and password reset, and — viakey_fnplus open path targeting — any route or route group…

Keyed rate limiting middleware.

Provides a small in-memory limiter intended for authentication endpoints like login and password reset, and — viakey_fnplus open path targeting — any route or route group (per-user, per-resource, per-tenant). Supports pluggable backends (theRateLimitBackendProtocol) for Redis-backed rate limiting across workers.

The plain default 429 body is text. Seterror_template(and optionally error_block) to render a self-contained HTML 429 for htmx form-action POSTs — the middleware renders the template/block to aResponseitself (middleware returnsAnyResponse, never a Chirp return type), so the over-limit case stays decoupled from the handler's negotiation path.

middleware.auth_rate_limit

Name Type Default Description
type
qualified_name
element_type
description
source_file
line_number
is_autodoc
autodoc_element
_autodoc_template
_autodoc_url_path
_autodoc_page_type
title
doc_content_hash

Symbols on this page

RateLimitBackend
class

Protocol for rate limit storage backends.

AuthRateLimitConfig
class

Configuration for keyed rate limiting.

Defaults target the common auth endpoints keyed by trusted client IP. Setpaths=()to limit all matching-method routes, and supply key_fnto key on a per-user / per-resource / per-tenant identity instead of the client IP.

redis_rate_limit_backend
function
def redis_rate_limit_backend(redis_url: str, key_prefix: str = 'chirp:ratelimit:') -> RateLimitBackend

Create a Redis-backed rate limit backend. Requirespip install chirp[redis].

Parameters

Name Type Default Description
redis_url str
key_prefix str 'chirp:ratelimit:'
_InMemoryRateLimitBackend
class

In-memory rate limit backend.

AuthRateLimitMiddleware
class

Rate limiter for authentication-related endpoints.

View source · /home/runner/work/chirp/chirp/site/../src/chirp/middleware/auth_rate_limit.py:1