You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Sentinel中Global Throttle是什么?如何在Laravel项目中使用?

Hey there! Let me break down exactly what Global Throttle is in the context of Sentinel for Laravel, plus walk you through how to set it up and use it effectively.

What is Global Throttle?

Unlike user throttle (which limits requests per authenticated user) or ip throttle (which limits requests from a single IP address), global throttle applies a request limit across your entire application. It doesn’t care who’s making the request or where they’re coming from — it caps the total number of requests your app will accept within a specific time window.

This is super useful for protecting your entire application from large-scale abuse or traffic spikes that could overwhelm your server. For example, if a botnet hits your API endpoints from hundreds of different IPs, global throttle will kick in to prevent your app from being flooded.

How to Use Global Throttle with Sentinel

Step 1: Configure Global Throttle Settings

First, head to your config/sentinel.php file (if you don’t have it, publish Sentinel’s config with php artisan vendor:publish --provider="Cartalyst\Sentinel\Laravel\SentinelServiceProvider"). Look for the throttle section and add the global configuration:

'throttle' => [
    // Existing user and ip throttle configs...
    'user' => [
        'enabled' => true,
        'max_attempts' => 5,
        'decay_minutes' => 1,
    ],
    'ip' => [
        'enabled' => true,
        'max_attempts' => 10,
        'decay_minutes' => 1,
    ],
    // Add your global throttle config here
    'global' => [
        'enabled' => true,
        'max_attempts' => 150, // Adjust based on your app's capacity
        'decay_minutes' => 1, // Time window for the limit
    ],
],

Tweak max_attempts and decay_minutes to match your app’s needs — start with a reasonable number (like 100-200 requests per minute) and adjust based on your traffic patterns.

Step 2: Apply the Throttle Middleware

Next, you need to apply Sentinel’s throttle middleware to enforce the global limit. You have two options:

Option 1: Apply Globally to All Requests

If you want every request to your app to be subject to the global throttle, add the middleware to your global middleware stack in app/Http/Kernel.php:

protected $middleware = [
    // ... other global middleware
    \Cartalyst\Sentinel\Laravel\Middleware\ThrottleMiddleware::class,
];

When using this approach, the middleware will automatically check the global throttle rules for all incoming requests.

Option 2: Apply to Specific Routes/Router Groups

If you only want to protect specific parts of your app (like your API), apply the middleware to a route group in your routes file (e.g., routes/api.php):

Route::middleware('sentinel.throttle:global')->group(function () {
    // Your protected routes go here
    Route::post('/login', [AuthController::class, 'login']);
    Route::get('/products', [ProductController::class, 'index']);
    Route::post('/orders', [OrderController::class, 'store']);
});

This way, only the routes in this group will be bound by the global throttle limit.

Step 3: Customize the Throttle Response

By default, Sentinel will return a 429 Too Many Requests response when the global limit is hit. If you want a custom response (like a JSON message for your API), you can catch the ThrottleException in your exception handler:

Open app/Exceptions/Handler.php and add this to the register method:

use Cartalyst\Sentinel\Throttling\ThrottleException;

public function register()
{
    $this->renderable(function (ThrottleException $e, $request) {
        if ($request->expectsJson()) {
            return response()->json([
                'error' => 'Too many global requests',
                'message' => 'Please slow down and try again in ' . $e->getRetryAfter() . ' seconds.',
                'retry_after' => $e->getRetryAfter()
            ], 429);
        }

        return response('Too many requests. Please try again later.', 429);
    });
}

This will return a user-friendly JSON response for API requests, and a plain text response for web requests.


内容的提问来源于stack exchange,提问作者Sagar Shinde

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:58:34