Saltar para o conteúdo principal
Versão: Próximo

Web server quotas

Web applications can receive requests from many different clients, generating varying levels of traffic and resource consumption. Without appropriate limits, excessive activity from one or more clients can affect Web server performance and availability. Web server quotas let you control resource usage by limiting traffic, requests, active sessions, Guest sessions, and REST entity sets. Quotas can be configured at the web server global level (for all sessions combined), at the session default level (for each new session) or at the current REST session level.

Requisitos​

Quota configuration requires scalable sessions to be enabled.

How to configure quotas​

Na inicialização​

You can configure quotas using the quotas property passed to the start() function or (main Web server only) through a QuotaManager.json file.

Using the quotas property​

Quotas can be defined using the quotas property in the settings parameter passed to the start() function.


var $quotas:={}
$quotas.inBytesPerMin:=20000000

WEB Server().start({quotas: $quotas})

Using a QuotaManager.json file​

For the main Web server, you can create a QuotaManager.json file and store it in the Project/Sources folder. This file will loaded at startup by the main Web server. The file must contain a JSON object whose properties are quota property names:

/Project/Sources/QuotaManager.json
{
"inBytesPerHour": 100000000,
"inBytesPerHourPerSession": 10000000,
"nbRequestsPerMin": 1000,
"nbRequestsPerMinPerSession": 100
}

If the QuotaManager.json file contains malformed JSON, the Web server does not start and returns error 551 - JSON malformed.

When both a settings.quotas property and a QuotaManager.json file are provided, the settings.quotas configuration takes priority.

At runtime​

For a running Web server, you can update quotas through the WebServer.quotas property. Changes are applied to subsequent Web server activity; session default quotas apply to new sessions created after the quota value is updated.

Current REST session quotas​

The Session.quotas property configures quotas for the current REST session. It provides current usage values and lets you configure the session's REST entity-set limits and timeouts. These quotas are distinct from the session default quotas configured through WebServer.quotas, which are applied when new Web sessions are created.

Exemplo​

The following example configures web server quotas at startup for an internal application used by approximately 20 people with occasional usage:


var $quotas:={}

// Maximum number of input bytes accepted in a one-minute time window on the web server
$quotas.inBytesPerMin:=20000000

// Maximum number of output bytes sent in a one-minute time window for a session
$quotas.outBytesPerMinPerSession:=10000000

// Maximum number of active sessions on the web server
$quotas.nbSessions:=50

// Maximum number of unauthenticated sessions on the web server
$quotas.nbGuestSessions:=10

// Maximum number of requests accepted in a one-minute time window on the web server
$quotas.nbRequestsPerMin:=500

// Maximum number of requests accepted in a one-hour time window on the web server
$quotas.nbRequestsPerHour:=20000

// We launch the main Web server
WEB Server().start({quotas: $quotas})

Quota enforcement​

For each incoming request, the Web server checks quotas during preprocessing, before the On Web Connection database method is called (if defined):

  1. If a session quota is configured, it is checked first.
  2. If the request is accepted, the server global quota is checked.
  3. If both checks pass, the request is processed.

If either quota is exceeded, the request is rejected with an HTTP 429 Too Many Requests response. No web process is created and On Web Connection is not called (if defined).

If an output byte quota is exceeded while a response is being sent, the current request is interrupted. The preprocessing rules above apply to the next request in the same time window.

Rate limiting responses​

Rate-limiting quotas use fixed time windows. When a quota is reached, subsequent requests are rejected until the current one-minute or one-hour window ends. The HTTP 429 Too Many Requests response includes a Retry-After header containing the time to wait before sending another request.

When one of concurrent quotas (nbSessions, nbGuestSessions, and nbEntitySetsPerSession) is reached, the response includes an empty Retry-After header until the quota is no longer reached.

The input byte quotas apply to all data received for a request, including its headers and body. The output byte quotas are evaluated against the uncompressed response size, regardless of the Web server compression settings.

Quota values​

Quota limits must be positive integers. An Undefined value means that the quota is not configured and is not enforced. Values less than or equal to zero or values that are not integers are treated as Undefined.

Quota counters are stored in memory for each 4D Server instance and are not shared between multiple server instances.

Component Web servers​

Quotas configured for a component Web server apply only to that server and are independent of the quotas configured for the host Web server or other component Web servers.

The QuotaManager.json configuration file applies only to the main Web server. Component Web servers must be configured with the Web server .quotas property and/or the session .quotas property.

Veja também​