Skip to content

Rate Limiting

Beto Ramirez edited this page Aug 15, 2026 · 1 revision

Rate limiting (Common/RateLimiting)

Un único límite global (ventana fija) aplicado a toda la API por defecto — un endpoint nuevo queda protegido sin declarar nada. Partido por:

  • Usuario autenticado (claim NameIdentifier del JWT), si hay token.
  • IP del cliente, si es anónimo — así un cliente anónimo abusivo no consume el cupo de otro.

Configurable en la sección RateLimiting (PermitLimit, WindowSeconds, QueueLimit; ver appsettings.json para los defaults). Se lee vía IOptionsMonitor<RateLimitingOptions> por request, no una vez al arrancar — necesario para que overrides de configuración posteriores a AddAppRateLimiting() (tests, un reload en caliente) se respeten.

Al exceder el límite, responde 429 como ProblemDetails (mismo formato que el resto de los errores, Manejo-Global-de-Errores) con un header Retry-After. GET /health/live y /health/ready están exentos (.DisableRateLimiting() al mapearse): un orquestador les pega con mucha más frecuencia que cualquier cliente real, y si compartieran el límite global las probes fallarían por su propia frecuencia, no por un problema real — el orquestador terminaría reiniciando instancias sanas.

app.UseAppRateLimiting() va después de UseAuthentication() (necesita HttpContext.User resuelto para partir por usuario) y antes de UseAuthorization().


Ver también: CORS · Health-Checks · Home

Clone this wiki locally