Your command center to manage instances, permissions and billing.
Instances
An Instance is a virtual server that stores data and runs your application code.
Marketplace
Hosts applications, tools, and various files that you can download and install into an Instance.
Partners
Partners are experts in designing, building, and maintaining apps on Insites.
Support
Contact Insites Support for bugs, feature requests, and software development help.
Instantly available virtual server with built-in
features for your entire team.
CRM
CRM helps manage relationships with customers, suppliers, and third parties efficiently.
Assets
Insites enables you to upload and manage files such as images, and documents using Assets.
CMS
Manage your application content with ease via no-code builders.
Forms
Creating forms for users to input data into the system.
Pipelines
Your instance includes 'Pipelines' to manage opportunities by creating relevant stages.
Permissions
Manage user permissions and security for your application.
Data
Insites lets users view, create, and manage databases and content via the Instance Admin.
Ecommerce
The Insites Ecommerce module provides complete management of ecommerce activities.
Locator
The Locator lets you integrate your instance with Google Maps and customize it as you wish.
Events
Insites Events lets you manage schedules, tickets, and sponsorship on your instance.
API
Integrate with any tool or platform with bespoke Endpoints.
AI
Take advantage of the latest AI technology with your data.
A cohesive set of guidelines, patterns, and assets for a consistent, user-centered design.
Design System Overview
The Insites design system is a collection of reusable components, guided by clear standards.
Component Hierarchy
Learn how to customize components and how to structure your designs so they inherit attributes.
Font Icons
A full suite of font icons to use across your project within menus, buttons and quick links.
Color Styles
Figma color styles represent variables for Insites components, enabling quick customization.
Build blazing-fast, consistent user interfaces with our web component library.
General
A wide variety or general use components such as buttons, carousel, gallery, headings, and loaders.
Layout
Useful layout components such as an accordion, backdrop, drawer, headers, modals, and more.
Data Entry
Collect data with components that include card select, checkbox, inputs, sliders, and editors.
Data Display
Create engaging interfaces with components such as Kanban boards, charts, tables, and timelines.
Tutorials, references, and examples on how to build modern web applications on Insites.
Development
Covers key topics for setting up and maintaining web applications on Insites.
Modules
Modules enable code reuse and sharing while protecting creators' intellectual property.
Pages and Layouts
Learn how to implement pages and rendering content on your Instance.
Databases and Users
Discover how to create custom data models, import/export data and manage users.
The Insites CLI Tool helps you deploy configuration
files and assets to your Insites Instance.
Get Started
Guides you through the requirements and steps to install and start using the Insites CLI Tool.
Commands and Options
Learn the commands and options for managing configurations in the Insites CLI.
Graphical User Interface
Discover how using the GUI can enhance your workflow by simplifying complex processes.
Code Linting
Automatically check your codebase for programmatic and stylistic errors when deploying.
GraphQL
A data query and manipulation language that allows you to specify the data you require.
Liquid
Liquid is a template language for creating dynamic pages, content and configurations.
API Docs
Learn about the functionalities and structure of the inbuilt API Endpoints of your instance.
Web Applications
Discover how to create your web application with step by step guides and helpful examples.
Your command center to manage instances, permissions and billing.
Instances
An Instance is a virtual server that stores data and runs your application code.
Marketplace
Hosts applications, tools, and various files that you can download and install into an Instance.
Partners
Partners are experts in designing, building, and maintaining apps on Insites.
Support
Contact Insites Support for bugs, feature requests, and software development help.
Instantly available virtual server with built-in
features for your entire team.
CRM
CRM helps manage relationships with customers, suppliers, and third parties efficiently.
Assets
Insites enables you to upload and manage files such as images, and documents using Assets.
CMS
Manage your application content with ease via no-code builders.
Forms
Creating forms for users to input data into the system.
Pipelines
Your instance includes 'Pipelines' to manage opportunities by creating relevant stages.
Permissions
Manage user permissions and security for your application.
Data
Insites lets users view, create, and manage databases and content via the Instance Admin.
Ecommerce
The Insites Ecommerce module provides complete management of ecommerce activities.
Locator
The Locator lets you integrate your instance with Google Maps and customize it as you wish.
Events
Insites Events lets you manage schedules, tickets, and sponsorship on your instance.
API
Integrate with any tool or platform with bespoke Endpoints.
AI
Take advantage of the latest AI technology with your data.
A cohesive set of guidelines, patterns, and assets for a consistent, user-centered design.
Design System Overview
The Insites design system is a collection of reusable components, guided by clear standards.
Component Hierarchy
Learn how to customize components and how to structure your designs so they inherit attributes.
Font Icons
A full suite of font icons to use across your project within menus, buttons and quick links.
Color Styles
Figma color styles represent variables for Insites components, enabling quick customization.
Build blazing-fast, consistent user interfaces with our web component library.
General
A wide variety or general use components such as buttons, carousel, gallery, headings, and loaders.
Layout
Useful layout components such as an accordion, backdrop, drawer, headers, modals, and more.
Data Entry
Collect data with components that include card select, checkbox, inputs, sliders, and editors.
Data Display
Create engaging interfaces with components such as Kanban boards, charts, tables, and timelines.
Tutorials, references, and examples on how to build modern web applications on Insites.
Development
Covers key topics for setting up and maintaining web applications on Insites.
Modules
Modules enable code reuse and sharing while protecting creators' intellectual property.
Pages and Layouts
Learn how to implement pages and rendering content on your Instance.
Databases and Users
Discover how to create custom data models, import/export data and manage users.
The Insites CLI Tool helps you deploy configuration
files and assets to your Insites Instance.
Get Started
Guides you through the requirements and steps to install and start using the Insites CLI Tool.
Commands and Options
Learn the commands and options for managing configurations in the Insites CLI.
Graphical User Interface
Discover how using the GUI can enhance your workflow by simplifying complex processes.
Code Linting
Automatically check your codebase for programmatic and stylistic errors when deploying.
GraphQL
A data query and manipulation language that allows you to specify the data you require.
Liquid
Liquid is a template language for creating dynamic pages, content and configurations.
API Docs
Learn about the functionalities and structure of the inbuilt API Endpoints of your instance.
Web Applications
Discover how to create your web application with step by step guides and helpful examples.
Your command center to manage instances, permissions and billing.
Instances
An Instance is a virtual server that stores data and runs your application code.
Marketplace
Hosts applications, tools, and various files that you can download and install into an Instance.
Partners
Partners are experts in designing, building, and maintaining apps on Insites.
Support
Contact Insites Support for bugs, feature requests, and software development help.
Instantly available virtual server with built-in features for your entire team.
CRM
CRM helps manage relationships with customers, suppliers, and third parties efficiently.
Assets
Insites enables you to upload and manage files such as images, and documents using Assets.
CMS
Manage your application content with ease via no-code builders.
Forms
Creating forms for users to input data into the system.
Pipelines
Your instance includes 'Pipelines' to manage opportunities by creating relevant stages.
Permissions
Manage user permissions and security for your application.
Data
Insites lets users view, create, and manage databases and content via the Instance Admin.
Ecommerce
The Insites Ecommerce module provides complete management of ecommerce activities.
Locator
The Locator lets you integrate your instance with Google Maps and customize it as you wish.
Events
Insites Events lets you manage schedules, tickets, and sponsorship on your instance.
API
Integrate with any tool or platform with bespoke Endpoints.
AI alpha
Take advantage of the latest AI technology with your data.
A cohesive set of guidelines, patterns, and assets for a consistent, user-centered design.
Design System Overview
The Insites design system is a collection of reusable components, guided by clear standards.
Component Hierarchy
Learn how to customize components and how to structure your designs so they inherit attributes.
Font Icons
A full suite of font icons to use across your project within menus, buttons and quick links.
Color Styles
Figma color styles represent variables for Insites components, enabling quick customization.
Build blazing-fast, consistent user interfaces with our web component library.
General
A wide variety or general use components such as buttons, carousel, gallery, headings, and loaders.
Layout
Useful layout components such as an accordion, backdrop, drawer, headers, modals, and more.
Data Entry
Collect data with components that include card select, checkbox, inputs, sliders, and editors.
Data Display
Create engaging interfaces with components such as Kanban boards, charts, tables, and timelines.
Tutorials, references, and examples on how to build modern web applications on Insites.
Development
Covers key topics for setting up and maintaining web applications on Insites.
Modules
Modules enable code reuse and sharing while protecting creators' intellectual property.
Pages and Layouts
Learn how to implement pages and rendering content on your Instance.
Databases and Users
Discover how to create custom data models, import/export data and manage users.
The Insites CLI Tool helps you deploy configuration
files and assets to your Insites Instance.
Get Started
Guides you through the requirements and steps to install and start using the Insites CLI Tool.
Commands and Options
Learn the commands and options for managing configurations in the Insites CLI.
Graphical User Interface
Discover how using the GUI can enhance your workflow by simplifying complex processes.
Code Linting
Automatically check your codebase for programmatic and stylistic errors when deploying.
GraphQL
A data query and manipulation language that allows you to specify the data you require.
Liquid
Liquid is a template language for creating dynamic pages, content and configurations.
API Docs
Learn about the functionalities and structure of the inbuilt API Endpoints of your instance.
Web Applications
Discover how to create your web application with step by step guides and helpful examples.
Count attempts per visitor address, refuse with too_many, and lock out repeat failures safely.
Rate limiting stops one visitor from trying again and again, for example guessing sign-in codes. On Insites you build it with two tables and a few lines of Liquid. You count failed attempts per visitor address over a time window. When there are too many, you refuse with too_many. After repeated failures you lock the address out, and each lockout is longer than the last.
Request headers are in context.headers. They are not stored under their HTTP names. Each name is uppercased, every hyphen becomes an underscore, and HTTP_ is added in front. So X-Forwarded-For is read as context.headers.HTTP_X_FORWARDED_FOR. A read such as context.headers['X-Forwarded-For'] is always blank.
X-Forwarded-For can hold several addresses, separated by commas. The visitor address is the first entry. It is the same value as X-Real-IP, read as context.headers.HTTP_X_REAL_IP. The network edge in front of your instance replaces both headers with the address it saw, so a visitor cannot choose either value.
X-Forwarded-For. It is an internal address that changes from request to request. A limit on it counts per server, not per visitor.True-Client-IP or Forwarded. They pass through whatever the visitor sends.Read the address in one partial, and call it from every page that needs it:
app/views/partials/client_ip.liquid
{%- comment -%}
The visitor network address, for rate limits. Called with:
function ip = 'client_ip'
X-Real-IP and the FIRST X-Forwarded-For entry hold the address the edge saw, and the
edge replaces whatever the client sent in either header. The LAST X-Forwarded-For
entry is an internal address, so never limit on it.
{%- endcomment -%}
{%- liquid
assign ip = context.headers.HTTP_X_REAL_IP
if ip == blank
assign xff = context.headers.HTTP_X_FORWARDED_FOR | default: 'unknown'
assign ip = xff | split: ',' | first | strip
endif
assign ip = ip | truncate: 60, ''
return ip
-%}
{% liquid
function ip = 'client_ip'
%}
<p>Your address: {{ ip | escape }}</p>
One row in login_attempt is one failed attempt. One row in ip_lockout is one lockout.
app/schema/login_attempt.yml
name: login_attempt
properties:
- name: ip
type: string
app/schema/ip_lockout.yml
name: ip_lockout
properties:
- name: ip
type: string
- name: minutes
type: integer
Every record gets created_at automatically, so neither table needs a time field.
Table and field names are passed in as variables, not written into the query.
app/graphql/records/find_by.graphql
query find_by($table: String!, $field: String!, $value: String!, $limit: Int!) {
records(
per_page: $limit
filter: { table: { value: $table }, properties: [{ name: $field, value: $value }] }
sort: [{ created_at: { order: DESC } }]
) {
total_entries
results { id created_at properties }
}
}
app/graphql/records/create.graphql
mutation create($table: String!, $properties: [PropertyInputType]) {
record_create(record: { table: $table, properties: $properties }) { id }
}
This partial answers true when the address is locked out or has too many recent failures. Field values come back under properties, as text, so plus: 0 turns minutes into a number.
app/views/partials/rate_limit/blocked.liquid
{% liquid
assign blocked = false
graphql locks = 'records/find_by', table: 'ip_lockout', field: 'ip', value: ip, limit: 1
assign lock = locks.records.results.first
if lock
assign age = lock.created_at | time_diff: 'now', 's'
assign minutes = lock.properties.minutes | plus: 0
assign lock_seconds = minutes | times: 60
if age < lock_seconds
assign blocked = true
endif
endif
graphql recent = 'records/find_by', table: 'login_attempt', field: 'ip', value: ip, limit: 5
if recent.records.results.size >= 5
assign oldest = recent.records.results | last
assign age = oldest.created_at | time_diff: 'now', 's'
if age < 900
assign blocked = true
endif
endif
return blocked
%}
Call it at the top of the page you protect, and refuse with status 429:
{% liquid
function ip = 'client_ip'
function blocked = 'rate_limit/blocked', ip: ip
if blocked
response_status 429
assign body = {}
assign body.error = 'too_many'
assign out = body | json
echo out
break
endif
%}
Call this partial whenever an attempt fails, for example when a sign-in code is wrong. It saves the failure. When the address reaches 5 failures in 15 minutes, it adds a lockout. The first lockout is 15 minutes. Each later lockout for the same address is twice as long, up to 24 hours.
app/views/partials/rate_limit/record_failure.liquid
{% liquid
assign attempt_ip = {}
assign attempt_ip.name = 'ip'
assign attempt_ip.value = ip
assign attempt_props = []
assign attempt_props = attempt_props | add_to_array: attempt_ip
graphql saved = 'records/create', table: 'login_attempt', properties: attempt_props
graphql recent = 'records/find_by', table: 'login_attempt', field: 'ip', value: ip, limit: 5
if recent.records.results.size < 5
return false
endif
assign oldest = recent.records.results | last
assign age = oldest.created_at | time_diff: 'now', 's'
if age >= 900
return false
endif
graphql earlier = 'records/find_by', table: 'ip_lockout', field: 'ip', value: ip, limit: 1
assign lockouts_before = earlier.records.total_entries
assign minutes = 15
for i in (1..lockouts_before)
assign minutes = minutes | times: 2
if minutes >= 1440
assign minutes = 1440
break
endif
endfor
assign lock_ip = {}
assign lock_ip.name = 'ip'
assign lock_ip.value = ip
assign lock_minutes = {}
assign lock_minutes.name = 'minutes'
assign lock_minutes.value_int = minutes
assign lock_props = []
assign lock_props = lock_props | add_to_array: lock_ip | add_to_array: lock_minutes
graphql locked = 'records/create', table: 'ip_lockout', properties: lock_props
return true
%}
{% function locked = 'rate_limit/record_failure', ip: ip %}
too_many.records query stops returning them straight away.Didn't quite find what you are looking for or have feedback on how we can make the content better then we would love to hear from you. Please provide us feedback and we will get back to you shortly.