Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, correct. However depending on the proxy/tool doing the rate limiting it may be easier to limit based on a key in a separate cookie or header than extracting from a signed cookie. Even if the other cookie or header is logically covered by that signature keeping it more separate may make it easier overall.


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: