Skip to content

Releases: jacyimp/api-platform-rate-limiter

v0.2.0 - Simplified metadata API

Choose a tag to compare

@jacyimp jacyimp released this 06 Sep 17:30

v0.2.0

This release simplifies the public API and removes several unnecessary metadata abstractions.

Breaking changes

  • RateLimit metadata is now added directly to extraProperties
  • Multiple RateLimit entries can be declared naturally and are composed together
  • Resource-level and operation-level limits now combine instead of replacing each other
  • Removed DynamicLimit, DynamicCost, DynamicBucket, Identity, and Condition
  • Dynamic values now use typed resolver class names via class-string<T>
  • Dynamic buckets now use the explicit bucketResolver option
  • Removed the custom Interval value object; use strings or native DateInterval
  • Removed the RateLimitChecking lifecycle event

Improvements

  • Simplified identity and condition composition

  • Clarified bucket vs identity semantics for tenant-aware limits

  • Fixed misleading tenant quota documentation

  • Made symfony/security-core optional

    • authenticated Symfony users are rate limited by user identity when Security is installed
    • applications without Symfony Security fall back cleanly to client IP
  • Reduced metadata boilerplate and internal complexity

Example:

new Post(
    extraProperties: [
        new RateLimit(
            limit: 100,
            interval: '1 minute',
        ),
        new RateLimit(
            limit: 1_000,
            interval: '1 hour',
        ),
        new RateLimit(
            limit: 10_000,
            interval: '1 day',
        ),
    ],
)

v0.1.2

Choose a tag to compare

@jacyimp jacyimp released this 01 Sep 16:33
  • Fix Laravel rate-limit rejections returning 500 instead of 429.
  • Prevent stale request state in long-lived Laravel applications.
  • Enable automatic Symfony bundle registration with Symfony Flex.

v0.1.1

Choose a tag to compare

@jacyimp jacyimp released this 01 Sep 12:33

v0.1.1

Fixed

  • Fix rate limiting on stateless Symfony/API Platform applications.
  • Remove dependency on use_symfony_listeners: true.
  • Resolve API Platform operations directly from route metadata.
  • Avoid session usage when resolving authenticated identities on stateless requests.

v0.1.0

Choose a tag to compare

@jacyimp jacyimp released this 01 Sep 07:07

v0.1.0

First public release of API Platform Rate Limiter.

Highlights:

  • Operation, resource, global, and shared-bucket rate limits
  • Symfony and Laravel support
  • Dynamic limits, buckets, and costs
  • Composable identities and conditions
  • Conditional and request-wide bypasses
  • Runtime rate-limit providers
  • Fixed and sliding windows
  • Weighted request costs
  • Custom rejection handling and lifecycle events
  • PHP 8.2–8.5 support