How would you add basic rate limiting to an Express or Spring login route?
PICTURE THIS: HOW TO EXPLAIN IT
Simple meaning
Key by IP plus username, count hits in Redis with an INCR and TTL window, and return 429 when the cap is exceeded.
WHY — Rate limiting instead of guessing?
Why interviewers care about Rate limiting:
question about Rate limiting.
trade-offs, and what you would actually do on a Backend project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Key by IP plus
username, count hits in Redis with an INCR and TTL window, and return 429 when the cap is exceeded.
- 2In-memory maps fail as
soon as you have two instances.
- 3Login and OTP endpoints
need stricter limits than public catalog GETs.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Key by IP plus username, count hits in Redis with an INCR and TTL window, and return 429 when the cap is exceeded. In-memory maps fail as soon as you have two instances.