xlock
Server-side bot protection middleware for Ruby. Works with Rack, Rails, or standalone.
Installation
Add to your Gemfile:
gem "xlock"
Then run bundle install.
Usage
Rails Controller
class ApplicationController < ActionController::Base
include XLock::Rails
protect_with_xlock only: [:create, :login],
site_key: ENV["XLOCK_SITE_KEY"]
end
Options: site_key, api_url, fail_open (default true).
Rack Middleware
use XLock::Rack,
site_key: ENV["XLOCK_SITE_KEY"],
protected_paths: ["/api/auth", "/api/login"]
Only POST requests to the listed paths are checked. If protected_paths is empty, all POST requests are checked.
Direct Verification
result = XLock.verify(
token: "...",
site_key: ENV["XLOCK_SITE_KEY"],
path: "/api/login"
)
if result.blocked
puts "Blocked: #{result.reason}"
elsif result.error
puts "Error: #{result.error}"
else
puts "Allowed"
end
Configuration
Set XLOCK_SITE_KEY and optionally XLOCK_API_URL as environment variables, or pass them directly as options.
License
MIT