Cookbook
Auth
Stable
Rate Limiting, IP Allowlists & a Request Audit Trail
Rack::Attack throttles for login brute-force and request floods, a trusted-IP safelist, an optional country allowlist, and a UserEvent audit log that records who did what from which IP. Includes the two silent failures that make throttling do nothing at all.