Table of Contents

Class RateLimitParameters

Namespace
Cloudflare.NET.Security.Rulesets.Models
Assembly
Cloudflare.NET.dll

Defines the configuration for a rate limiting rule.

public record RateLimitParameters : IEquatable<RateLimitParameters>
Inheritance
RateLimitParameters
Implements
Inherited Members

Constructors

RateLimitParameters(IReadOnlyList<string>, int, int, int?, int?, bool?, string?, string?, bool?)

Defines the configuration for a rate limiting rule.

public RateLimitParameters(IReadOnlyList<string> Characteristics, int Period, int MitigationTimeout, int? RequestsPerPeriod = null, int? ScorePerPeriod = null, bool? RequestsToOrigin = null, string? CountingExpression = null, string? ScoreResponseHeaderName = null, bool? Simulate = null)

Parameters

Characteristics IReadOnlyList<string>

The properties to track for rate limiting (e.g., "ip.src").

Period int

The time period in seconds. Only specific values are allowed. It is highly recommended to use the constants defined in SecurityConstants.RateLimiting.Periods to avoid errors.

MitigationTimeout int

The duration in seconds to apply the mitigation action.

RequestsPerPeriod int?

The number of requests allowed in the period for standard rate limiting.

ScorePerPeriod int?

The score threshold for complexity-based rate limiting.

RequestsToOrigin bool?

Whether to count requests to origin (ignores cache).

CountingExpression string

A filter expression to specify which requests to count.

ScoreResponseHeaderName string

For complexity-based limiting, the name of the response header to send the score.

Simulate bool?

If true, the rule will be logged but not actioned.

Properties

Characteristics

The properties to track for rate limiting (e.g., "ip.src").

[JsonPropertyName("characteristics")]
public IReadOnlyList<string> Characteristics { get; init; }

Property Value

IReadOnlyList<string>

CountingExpression

A filter expression to specify which requests to count.

[JsonPropertyName("counting_expression")]
public string? CountingExpression { get; init; }

Property Value

string

MitigationTimeout

The duration in seconds to apply the mitigation action.

[JsonPropertyName("mitigation_timeout")]
public int MitigationTimeout { get; init; }

Property Value

int

Period

The time period in seconds. Only specific values are allowed. It is highly recommended to use the constants defined in SecurityConstants.RateLimiting.Periods to avoid errors.

[JsonPropertyName("period")]
public int Period { get; init; }

Property Value

int

RequestsPerPeriod

The number of requests allowed in the period for standard rate limiting.

[JsonPropertyName("requests_per_period")]
public int? RequestsPerPeriod { get; init; }

Property Value

int?

RequestsToOrigin

Whether to count requests to origin (ignores cache).

[JsonPropertyName("requests_to_origin")]
public bool? RequestsToOrigin { get; init; }

Property Value

bool?

ScorePerPeriod

The score threshold for complexity-based rate limiting.

[JsonPropertyName("score_per_period")]
public int? ScorePerPeriod { get; init; }

Property Value

int?

ScoreResponseHeaderName

For complexity-based limiting, the name of the response header to send the score.

[JsonPropertyName("score_response_header_name")]
public string? ScoreResponseHeaderName { get; init; }

Property Value

string

Simulate

If true, the rule will be logged but not actioned.

[JsonPropertyName("simulate")]
public bool? Simulate { get; init; }

Property Value

bool?