/** * src/oauth/rate-limit.ts — Simple per-IP rate limiter for the token endpoint. * * No external dependencies — uses a plain Map + setInterval for cleanup. * * Usage: * app.use("/oauth/token", createRateLimiter({ windowMs: 60_000, maxRequests: 10 })); */ import type { Request, Response, NextFunction } from "express"; export interface RateLimiterOptions { windowMs: number; maxRequests: number; trustProxy?: boolean; } /** * Creates a rate-limiting Express middleware. * * Returns 429 with Retry-After header when the per-IP limit is exceeded. */ export declare function createRateLimiter(options: RateLimiterOptions): (req: Request, res: Response, next: NextFunction) => void;