Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We usually implement queueing on the route to those specific things that are vulnarable. If you can not discern what traffic does what, you just need move the rate limiter close to the application or the problem hot spot. It's perfectly valid to give a HTTPS response 429 from a backend and let your frontend handle that in some graceful way. The same is valid as an exception in code, the nearer the problem spot you get the harder it is to get right.

EDIT clarification.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: