I'm using https://github.com/kickstarter/rack-attack/#throttles to throttle request to certain url's.
Rack-attack docs show how to throttle by request IP or request parameters, but what I'd like to do is throttle requests per user. So no matter the IP, user should be able to make no more than n request in certain time frame.
We use devise for authentication and I cannot think of a simple way to uniquely identify users based on request.
Should I store user id in the session/cookie? Maybe a uniq hash? What's you opinion on the best way to go about doing that?
request content type
e.g.application/javascript
ortext/html
in thethrottled_response
method? #36305493 – Lapointe