Skip to content

Use MetadataName.RetryAfter in rate limiting OnRejected example and add .NET 11 note - #37762

Open
guardrex with Copilot wants to merge 2 commits into
mainfrom
copilot/update-rate-limiting-retry-after-headers
Open

guardrex with Copilot wants to merge 2 commits into
mainfrom
copilot/update-rate-limiting-retry-after-headers

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

The OnRejected example in the rate limiting article hard-codes Retry-After: 60 and doesn't mention that in .NET 11 FixedWindowRateLimiter reports an accurate RetryAfter metadata value. This PR updates the example and adds a version-scoped note.

  • OnRejected example (aspnetcore/performance/rate-limit.md)

    • The hard-coded header is replaced with a read of MetadataName.RetryAfter from context.Lease. The header is set only when the limiter provides that metadata. This matches the pattern in rate-limit-samples.md.
    • A line after the example lists the required using System.Globalization; and using System.Threading.RateLimiting;.
    if (context.Lease.TryGetMetadata(MetadataName.RetryAfter, out var retryAfter))
    {
        context.HttpContext.Response.Headers.RetryAfter =
            ((int)retryAfter.TotalSeconds).ToString(NumberFormatInfo.InvariantInfo);
    }
  • .NET 11 note

    • A > [!NOTE] under :::moniker range=">= aspnetcore-11.0" says fixed-window rejections now report the next window boundary. It also says limiters that can't estimate availability, such as ConcurrencyLimiter, provide no metadata.
    • The surrounding >= aspnetcore-7.0 zone is closed and reopened around the note. The article now has three moniker openers and closers.
  • Metadata: ms.date is updated.

Review notes:

  • The <xref:System.Threading.RateLimiting.*> UIDs (FixedWindowRateLimiter, ConcurrencyLimiter) are taken from the issue's proposed text. They haven't been checked against the API docs or the OpenPublishing build.
  • The MetadataName.RetryAfter pattern is valid on earlier versions, so the example is unscoped and only the note is .NET 11-only.

Internal previews

File Preview link
aspnetcore/performance/rate-limit.md Learn preview

Build report

Co-authored-by: guardrex <1622880+guardrex@users.noreply.github.com>
Copilot AI changed the title [WIP] Update rate limiting middleware article for accurate Retry-After headers Use MetadataName.RetryAfter in rate limiting OnRejected example and add .NET 11 note Oct 2, 2026
Copilot AI requested a review from guardrex October 2, 2026 10:36
@guardrex
guardrex marked this pull request as ready for review October 2, 2026 10:43
@guardrex
guardrex requested a review from wtgodbe October 2, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v11 update: Accurate rate-limiting Retry-After headers

2 participants