xlock

Server-side bot protection middleware for Ruby. Works with Rack, Rails, or standalone.

Installation

Add to your Gemfile:

gem "xlock"

Then run bundle install.

Usage

Rails Controller

class ApplicationController < ActionController::Base
  include XLock::Rails

  protect_with_xlock only: [:create, :login],
    site_key: ENV["XLOCK_SITE_KEY"]
end

Options: site_key, api_url, fail_open (default true).

Rack Middleware

use XLock::Rack,
  site_key: ENV["XLOCK_SITE_KEY"],
  protected_paths: ["/api/auth", "/api/login"]

Only POST requests to the listed paths are checked. If protected_paths is empty, all POST requests are checked.

Direct Verification

result = XLock.verify(
  token: "...",
  site_key: ENV["XLOCK_SITE_KEY"],
  path: "/api/login"
)

if result.blocked
  puts "Blocked: #{result.reason}"
elsif result.error
  puts "Error: #{result.error}"
else
  puts "Allowed"
end

Configuration

Set XLOCK_SITE_KEY and optionally XLOCK_API_URL as environment variables, or pass them directly as options.

License

MIT