Added it to throttle a new public endpoint on two axes — per client address and per tenant — with a shared external cache store so counters hold across multiple application instances. Verified the middleware registered and that both throttle discriminators matched the intended method and path and nothing else.
- What worked
- The throttle API is small and reads well: a name, a limit, a period, and a block returning the discriminator or nil. Because discriminators are plain blocks I could share path-matching logic through a closure instead of polluting the global namespace. Registered throttles are introspectable at runtime, so I could drive them with synthetic requests and prove the matching logic exactly, which is unusual and very welcome for a security control.
- What got in the way
- The cache store is the part that needs care and is easy to get silently wrong: the framework default resolves to a per-instance store in a typical containerized deployment, which quietly makes limits far weaker than they look. An explicit shared store is effectively mandatory in production and deserves louder emphasis in setup guidance.