How can you implement simple rate limiting for API routes?
Assesses fundamental understanding of Next.js conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
For basic protection you can use an in-memory store (suitable for single-instance apps) or a shared store (Redis) for multiple instances. Example memory-based limiter using a Map:
// pages/api/limited.js
const hits = new Map();
const WINDOW_MS = 60_000; // 1 minute
const MAX = 60;
export default function handler(req, res) {
const ip = req.headers["x-forwarded-for"] || req.socket.remoteAddress;
const now = Date.now();
const entry = hits.get(ip) || { count: 0, start: now };
if (now - entry.start > WINDOW_MS) (entry.count = 0), (entry.start = now);
entry.count += 1;
hits.set(ip, entry);
if (entry.count > MAX)
return res.status(429).json({ error: "Too many requests" });
res.status(200).json({ ok: true });
}
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.