abolaradev / livewire-rate-limiter
rate limiter for livewire actions
Package info
github.com/abolaradev/Livewire-Rate-Limiter
pkg:composer/abolaradev/livewire-rate-limiter
Requires
- php: ^8.2
- illuminate/contracts: ^11.0||^12.0||^13.0
- illuminate/support: ^12.0||^13.0
- livewire/livewire: ^4.0
- spatie/laravel-package-tools: ^1.16
Requires (Dev)
- laravel/pint: ^1.14
- nunomaduro/collision: ^8.8
- orchestra/testbench: ^11.0.0||^10.0.0||^9.0.0
- pestphp/pest: ^4.0
- pestphp/pest-plugin-arch: ^4.0
- pestphp/pest-plugin-laravel: ^4.0
README
Rate Limiting is a technique used to control how many requests a user or client can make within a specific period of time. It helps protect applications from excessive requests, abuse, brute-force attempts, and unnecessary resource consumption.
Livewire Rate Limiter provides a simple way to apply Rate Limiting to Livewire Actions without having to implement the Rate Limiting logic manually.
Features
- Apply Rate Limiting to Livewire Actions using a PHP Attribute.
- Customize Rate Limiting settings for individual Actions.
- Apply Rate Limiting using the
LivewireRateLimiterFacade. - Define custom behavior when the Rate Limit is exceeded.
- Get the remaining time until the Rate Limit expires.
- Display custom content using the
@limitationBlade directive. - Automatically return an HTTP 429 (Too Many Requests) response when the Rate Limit is exceeded.
Installation
You can install the package via Composer:
composer require abolaradev/livewire-rate-limiter
You can publish the configuration file with:
php artisan vendor:publish --tag='livewire-rate-limiter-config'
Configuration
The package configuration is located at config/livewire-rate-limiter.php:
return [ /** * Maximum number of allowed attempts within the decay period. */ 'maxAttempts' => 10, /** * Number of seconds before the attempt counter is reset. */ 'decaySeconds' => 60, ];
Usage
Using the RateLimiter Attribute
To enable Rate Limiting for a Livewire Action, simply add the RateLimiter PHP Attribute to the desired method.
By default, the RateLimiter Attribute uses the values defined in the config/livewire-rate-limiter.php configuration file.
use Abolaradev\LivewireRateLimiter\Attributes\RateLimiter; use Livewire\Component; new class extends Component { #[RateLimiter()] public function oneTimePassword() { $this->send(); } };
Custom Rate Limiting
You can customize the Rate Limiting settings for a specific Livewire Action by passing values directly to the RateLimiter Attribute.
The maxAttempts argument defines the maximum number of allowed attempts, while decaySeconds specifies the number of seconds before the attempt counter is reset.
For example, the following Action allows 5 attempts within a 120-second period:
#[RateLimiter(maxAttempts: 5, decaySeconds: 120)] public function oneTimePassword() { $this->send(); }
Rate Limit Response
When the Rate Limit is exceeded, the package automatically returns an HTTP 429 (Too Many Requests) response and prevents the Livewire Action from continuing its execution.
Using the LivewireRateLimiter Facade
The package also provides an alternative way to apply Rate Limiting to Livewire Actions using the LivewireRateLimiter Facade.
Call the handle method within the desired Livewire Action. The onAction argument accepts a Closure containing the logic that should be executed when the request is allowed.
use Abolaradev\LivewireRateLimiter\Facades\LivewireRateLimiter; use Livewire\Component; new class extends Component { public function oneTimePassword() { LivewireRateLimiter::handle( onAction: fn () => $this->send() ); } };
Custom Limit Handling
The Facade-based approach allows you to define custom behavior when the Rate Limit is exceeded.
Pass a Closure to the handle method using the onLimit argument. This Closure is executed when the Rate Limit is exceeded.
public function oneTimePassword() { LivewireRateLimiter::handle( onAction: fn () => $this->send(), onLimit: fn () => $this->js("alert('Too Many Requests')") ); }
This allows you to return a custom response or perform any additional process when the Rate Limit is exceeded.
Getting the Remaining Time
You may need to know how many seconds remain until the current Rate Limit expires. The getAvailableIn() method returns the remaining time in seconds.
public int $available; public function oneTimePassword() { LivewireRateLimiter::handle( onAction: fn () => $this->send(), onLimit: fn () => $this->available = LivewireRateLimiter::getAvailableIn() ); }
Blade Directive
The package also provides a Blade conditional directive called @limitation.
It allows you to display custom content while the current Rate Limit is active.
@limitation <p class="text-red-500"> <span>{{ $available }}</span> seconds remaining until the rate limit expires! </p> @endlimitation
If you find this package useful, please don't forget to give it a ⭐ on GitHub. ❤️
Testing
Run the test suite with:
composer test
Changelog
Please see CHANGELOG for more information on what has changed recently.
Contributing
Please see CONTRIBUTING for details.
Security Vulnerabilities
Please review our security policy for information on how to report security vulnerabilities.
Credits
License
The MIT License (MIT). Please see License File for more information.
