import type { CanActivate, ExecutionContext, OnModuleDestroy } from '@nestjs/common'; import { Reflector } from '@nestjs/core'; import type { Request } from 'express'; import type { ThrottleOptions } from '../decorators/throttle.decorator.js'; import type { MastraModuleOptions } from '../mastra.module.js'; /** * Guard that implements rate limiting. * Rate limiting is ON by default - set rateLimitOptions.enabled: false to disable. */ export declare class MastraThrottleGuard implements CanActivate, OnModuleDestroy { private readonly options; private readonly reflector; private readonly logger; private readonly store; private cleanupInterval; constructor(options: MastraModuleOptions, reflector: Reflector); /** * Clean up the interval when the module is destroyed. */ onModuleDestroy(): void; canActivate(context: ExecutionContext): Promise; /** * Check rate limit for a request. * Can be called directly from controllers for manual rate limiting. */ checkLimit(request: Request, limit: number, windowMs: number, rateLimitPath?: string): Promise; /** * Get rate limit settings for this request. */ getRateLimitSettings(request: Request, decoratorOptions?: ThrottleOptions, rateLimitPath?: string): { limit: number; windowMs: number; }; /** * Get client identifier for rate limiting. * Uses user ID if authenticated, IP address otherwise. * * Security note: X-Forwarded-For is only trusted when the app is configured * with 'trust proxy' in Express. Without that setting, we use the direct * connection IP to prevent header spoofing attacks. */ private getClientId; /** * Evict oldest entries when store exceeds max size. * Uses a simple LRU-like approach based on resetAt time. */ private evictOldestEntries; /** * Clean up expired entries from the store. */ private cleanupExpiredEntries; } //# sourceMappingURL=mastra-throttle.guard.d.ts.map