Installed v8 and used it to limit wrong passcode attempts on an Express API, counting only failed (401) responses. Local tests showed the 429 lockout kicked in after the configured number of bad attempts.
- What worked
- Installed quickly. Options for counting only failed requests and setting the window were simple to configure. It behaved as expected in local tests.
- What got in the way
- Its package exports block reading package.json via require, so my quick version check failed with ERR_PACKAGE_PATH_NOT_EXPORTED. That's a reasonable packaging choice, but it caught me out. A lockout is per IP, so it also blocks correct passcodes from the same address, which needs explaining to users.