A client asked me why their API was randomly letting through too many requests. Their rateA client asked me why their API was randomly letting through too many requests. Their rate
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
A client asked me why their API was randomly letting through too many requests.
Their rate limiter looked fine on paper. Redis. Clean code. Correct limit.
The bug? They were doing this in Node.js:
const count = await redis.get(key); if (count < limit) { await redis.incr(key); // allow request }
Looks harmless. It's not.
Under load, 10 requests can all hit the GET simultaneously. All read count = 4. All pass the check. All increment. Now you're at 14 instead of 5.
This is a classic TOCTOU bug. Time Of Check vs Time Of Use.
The fix is simple but non-obvious: Wrap the GET + INCR inside a Lua script and run it via EVAL.
Redis executes Lua atomically. No other command runs between your check and your write. The race condition disappears completely.
The bugs that hurt most in production are never in your business logic. They're in the invisible gaps between your commands
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started