The existing rate limiting system rate-limits authenticated calls by identity and unauthenticated calls by IP. This is grand.
The part that's striking me as a bit strange right now is that there's probably a very strong case for authenticated users also having a higher (or at least different?) limits within a rate-limiting policy.
For this issue, a rate-limiting policy configuration should have a nullable property for an authenticated user to have a different window than the default. Of course, fall back to default if null.
The existing rate limiting system rate-limits authenticated calls by identity and unauthenticated calls by IP. This is grand.
The part that's striking me as a bit strange right now is that there's probably a very strong case for authenticated users also having a higher (or at least different?) limits within a rate-limiting policy.
For this issue, a rate-limiting policy configuration should have a nullable property for an authenticated user to have a different window than the default. Of course, fall back to default if null.