<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Ashutosh Pandey</title>
    <description>The latest articles on DEV Community by Ashutosh Pandey (@ashutosh_stark).</description>
    <link>https://dev.to/ashutosh_stark</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3780995%2Fb361eed0-11d1-4577-80ec-a21bbc646ce8.jpeg</url>
      <title>DEV Community: Ashutosh Pandey</title>
      <link>https://dev.to/ashutosh_stark</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/ashutosh_stark"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Ashutosh Pandey</dc:creator>
      <pubDate>Wed, 04 Mar 2026 20:55:15 +0000</pubDate>
      <link>https://dev.to/ashutosh_stark/-22a5</link>
      <guid>https://dev.to/ashutosh_stark/-22a5</guid>
      <description>&lt;div class="ltag__link"&gt;
  &lt;a href="/ashutosh_stark" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__pic"&gt;
      &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3780995%2Fb361eed0-11d1-4577-80ec-a21bbc646ce8.jpeg" alt="ashutosh_stark"&gt;
    &lt;/div&gt;
  &lt;/a&gt;
  &lt;a href="https://dev.to/ashutosh_stark/how-i-built-a-zero-latency-ai-firewall-in-spring-boot-without-redis-5ck6" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__content"&gt;
      &lt;h2&gt;Blocking AI Scrapers in Spring Boot Without Redis: A Lightweight Edge Filter&lt;/h2&gt;
      &lt;h3&gt;Ashutosh Pandey ・ Feb 19&lt;/h3&gt;
      &lt;div class="ltag__link__taglist"&gt;
        &lt;span class="ltag__link__tag"&gt;#webdev&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#ai&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#opensource&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#security&lt;/span&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/a&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>ai</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>[Boost]</title>
      <dc:creator>Ashutosh Pandey</dc:creator>
      <pubDate>Thu, 19 Feb 2026 15:35:37 +0000</pubDate>
      <link>https://dev.to/ashutosh_stark/-2ln0</link>
      <guid>https://dev.to/ashutosh_stark/-2ln0</guid>
      <description>&lt;div class="ltag__link"&gt;
  &lt;a href="/ashutosh_stark" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__pic"&gt;
      &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3780995%2Fb361eed0-11d1-4577-80ec-a21bbc646ce8.jpeg" alt="ashutosh_stark"&gt;
    &lt;/div&gt;
  &lt;/a&gt;
  &lt;a href="https://dev.to/ashutosh_stark/how-i-built-a-zero-latency-ai-firewall-in-spring-boot-without-redis-5ck6" class="ltag__link__link"&gt;
    &lt;div class="ltag__link__content"&gt;
      &lt;h2&gt;Defeating High-Velocity Scrapers at the Edge: A Spring Boot Drop-in (Without Redis)&lt;/h2&gt;
      &lt;h3&gt;Ashutosh Pandey ・ Feb 19&lt;/h3&gt;
      &lt;div class="ltag__link__taglist"&gt;
        &lt;span class="ltag__link__tag"&gt;#webdev&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#ai&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#programming&lt;/span&gt;
        &lt;span class="ltag__link__tag"&gt;#opensource&lt;/span&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/a&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>ai</category>
      <category>programming</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Blocking AI Scrapers in Spring Boot Without Redis: A Lightweight Edge Filter</title>
      <dc:creator>Ashutosh Pandey</dc:creator>
      <pubDate>Thu, 19 Feb 2026 12:09:43 +0000</pubDate>
      <link>https://dev.to/ashutosh_stark/how-i-built-a-zero-latency-ai-firewall-in-spring-boot-without-redis-5ck6</link>
      <guid>https://dev.to/ashutosh_stark/how-i-built-a-zero-latency-ai-firewall-in-spring-boot-without-redis-5ck6</guid>
      <description>&lt;h1&gt;
  
  
  Bots Found My API Before My Users Did
&lt;/h1&gt;

&lt;p&gt;If you expose a public API, something interesting happens.&lt;/p&gt;

&lt;p&gt;Within minutes, bots discover it.&lt;/p&gt;

&lt;p&gt;Headless browsers. AI scrapers. Random scripts running from cloud VMs.&lt;/p&gt;

&lt;p&gt;They start hammering endpoints, filling logs, consuming CPU, and quietly increasing your cloud bill before your real users even show up.&lt;/p&gt;

&lt;p&gt;The usual advice is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Just add Redis and implement rate limiting.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Which works — &lt;strong&gt;if you already run Redis&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;But for smaller services, side projects, or lean microservices, spinning up Redis just to block a few bots can feel like architectural overkill.&lt;/p&gt;

&lt;p&gt;I wanted something simpler.&lt;/p&gt;

&lt;p&gt;Something that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;lives inside the application&lt;/li&gt;
&lt;li&gt;adds almost zero latency&lt;/li&gt;
&lt;li&gt;blocks bots before they hit Spring Security&lt;/li&gt;
&lt;li&gt;requires &lt;strong&gt;zero external infrastructure&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So I built a small experiment called &lt;strong&gt;VelocityGate&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Move the Defense to the Earliest Possible Layer
&lt;/h1&gt;

&lt;p&gt;In Spring Boot, a request does &lt;strong&gt;not&lt;/strong&gt; go directly to your controller.&lt;/p&gt;

&lt;p&gt;It travels through several layers first:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Tomcat&lt;/li&gt;
&lt;li&gt;&lt;code&gt;DispatcherServlet&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Spring Security filters&lt;/li&gt;
&lt;li&gt;logging filters&lt;/li&gt;
&lt;li&gt;interceptors&lt;/li&gt;
&lt;li&gt;finally your &lt;code&gt;@RestController&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a bot sends &lt;strong&gt;100 requests per second&lt;/strong&gt;, letting those requests reach Spring Security is already expensive.&lt;/p&gt;

&lt;p&gt;You're allocating objects. Building security contexts. Possibly touching a database.&lt;/p&gt;

&lt;p&gt;That’s wasted work.&lt;/p&gt;

&lt;p&gt;So instead I added a filter that runs &lt;strong&gt;before everything else&lt;/strong&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="nd"&gt;@Bean&lt;/span&gt;
&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="nc"&gt;FilterRegistrationBean&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;BotBouncerFilter&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nf"&gt;velocityFilter&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="nc"&gt;FilterRegistrationBean&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;BotBouncerFilter&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;registrationBean&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;FilterRegistrationBean&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&amp;gt;();&lt;/span&gt;
    &lt;span class="n"&gt;registrationBean&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setFilter&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;BotBouncerFilter&lt;/span&gt;&lt;span class="o"&gt;());&lt;/span&gt;
    &lt;span class="n"&gt;registrationBean&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;addUrlPatterns&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"/*"&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;

    &lt;span class="c1"&gt;// Run before everything else&lt;/span&gt;
    &lt;span class="n"&gt;registrationBean&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;setOrder&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;Ordered&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;HIGHEST_PRECEDENCE&lt;/span&gt;&lt;span class="o"&gt;);&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;registrationBean&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This filter acts like a &lt;strong&gt;bouncer at the front door&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;If a request looks suspicious, it immediately returns a &lt;code&gt;403&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Which means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;no controller allocation&lt;/li&gt;
&lt;li&gt;no Spring Security processing&lt;/li&gt;
&lt;li&gt;no database calls&lt;/li&gt;
&lt;li&gt;no business logic execution&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The request dies instantly — exactly how it should.&lt;/p&gt;




&lt;h1&gt;
  
  
  In-Memory Rate Limiting (No Redis)
&lt;/h1&gt;

&lt;p&gt;For rate limiting I needed something:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;thread-safe&lt;/li&gt;
&lt;li&gt;extremely fast&lt;/li&gt;
&lt;li&gt;lock-free&lt;/li&gt;
&lt;li&gt;in-memory&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So I used a &lt;code&gt;ConcurrentHashMap&lt;/code&gt; with &lt;code&gt;AtomicInteger&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight java"&gt;&lt;code&gt;&lt;span class="kd"&gt;private&lt;/span&gt; &lt;span class="kd"&gt;final&lt;/span&gt; &lt;span class="nc"&gt;Map&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="nc"&gt;AtomicInteger&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;requestCounts&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;ConcurrentHashMap&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&amp;gt;();&lt;/span&gt;

&lt;span class="kd"&gt;public&lt;/span&gt; &lt;span class="kt"&gt;boolean&lt;/span&gt; &lt;span class="nf"&gt;isAllowed&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;String&lt;/span&gt; &lt;span class="n"&gt;ipAddress&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;limit&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
    &lt;span class="nc"&gt;AtomicInteger&lt;/span&gt; &lt;span class="n"&gt;count&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requestCounts&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;computeIfAbsent&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ipAddress&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt; &lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;AtomicInteger&lt;/span&gt;&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="o"&gt;));&lt;/span&gt;

    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="n"&gt;count&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="na"&gt;incrementAndGet&lt;/span&gt;&lt;span class="o"&gt;()&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;limit&lt;/span&gt;&lt;span class="o"&gt;)&lt;/span&gt; &lt;span class="o"&gt;{&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
    &lt;span class="o"&gt;}&lt;/span&gt;

    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="o"&gt;;&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That’s it.&lt;/p&gt;

&lt;p&gt;No network calls.&lt;br&gt;
No serialization.&lt;br&gt;
No distributed locks.&lt;/p&gt;

&lt;p&gt;Just atomic increments inside the JVM.&lt;/p&gt;

&lt;p&gt;A scheduled task clears the map periodically, effectively resetting the rate limit window.&lt;/p&gt;

&lt;p&gt;This works well for &lt;strong&gt;single-instance deployments or smaller services&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;If you run multiple replicas and need global synchronization, Redis or another centralized store is still the right approach.&lt;/p&gt;

&lt;p&gt;But for many APIs, this is more than enough.&lt;/p&gt;




&lt;h1&gt;
  
  
  Layer 2: Headless Browser Detection
&lt;/h1&gt;

&lt;p&gt;Rate limiting alone doesn’t stop &lt;strong&gt;slow scrapers&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;So VelocityGate also checks for common headless browser fingerprints.&lt;/p&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;HeadlessChrome&lt;/code&gt; in headers&lt;/li&gt;
&lt;li&gt;missing or suspicious &lt;code&gt;User-Agent&lt;/code&gt; values&lt;/li&gt;
&lt;li&gt;automation-related flags&lt;/li&gt;
&lt;li&gt;incomplete browser header sets&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you're running default Puppeteer or Playwright setups, many of those requests get blocked &lt;strong&gt;before the rate limiter even runs&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;So the defense becomes two layers:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Detect obvious automation immediately&lt;/li&gt;
&lt;li&gt;Throttle aggressive traffic&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Simple. Effective. Fast.&lt;/p&gt;




&lt;h1&gt;
  
  
  Why I Avoided Redis
&lt;/h1&gt;

&lt;p&gt;Redis is fantastic.&lt;/p&gt;

&lt;p&gt;But for this use case it introduces:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;network latency&lt;/li&gt;
&lt;li&gt;operational overhead&lt;/li&gt;
&lt;li&gt;another dependency&lt;/li&gt;
&lt;li&gt;more complexity during local development&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you're operating a globally distributed system, Redis absolutely makes sense.&lt;/p&gt;

&lt;p&gt;But if you're just trying to stop bots from melting a small API or VPS, an in-memory approach can be surprisingly effective.&lt;/p&gt;




&lt;h1&gt;
  
  
  Open Source Repo
&lt;/h1&gt;

&lt;p&gt;VelocityGate is open source here:&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://github.com/ashutosh-stark/velocity-gate" rel="noopener noreferrer"&gt;https://github.com/ashutosh-stark/velocity-gate&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Inside the repo you'll find:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the filter implementation&lt;/li&gt;
&lt;li&gt;header inspection logic&lt;/li&gt;
&lt;li&gt;the in-memory rate limiter&lt;/li&gt;
&lt;li&gt;configuration options&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It’s packaged as a &lt;strong&gt;Spring Boot starter&lt;/strong&gt; so it can be integrated quickly.&lt;/p&gt;




&lt;h1&gt;
  
  
  Exploring a Bigger Idea
&lt;/h1&gt;

&lt;p&gt;While working on this, something interesting came up.&lt;/p&gt;

&lt;p&gt;Someone asked whether this could work for &lt;strong&gt;Node or Bun&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Which made me realize the problem isn't really about Spring Boot.&lt;/p&gt;

&lt;p&gt;The real problem is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bots and AI scrapers hitting APIs and increasing infrastructure costs.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;So I'm exploring whether a &lt;strong&gt;language-agnostic gateway&lt;/strong&gt; might make sense.&lt;/p&gt;

&lt;p&gt;Something that sits in front of any backend:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Node.js&lt;/li&gt;
&lt;li&gt;Python&lt;/li&gt;
&lt;li&gt;Go&lt;/li&gt;
&lt;li&gt;Java&lt;/li&gt;
&lt;li&gt;PHP&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Basically a lightweight developer-focused API shield that blocks scraper traffic before it reaches your backend.&lt;/p&gt;

&lt;p&gt;Before investing months into building distributed synchronization and edge deployment, I want to validate whether developers actually need this.&lt;/p&gt;

&lt;p&gt;If this sounds interesting, you can join the early access waitlist here:&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://ashutosh-stark.github.io/velocitygate-cloud/" rel="noopener noreferrer"&gt;https://ashutosh-stark.github.io/velocitygate-cloud/&lt;/a&gt;&lt;/p&gt;




&lt;h1&gt;
  
  
  Final Thoughts
&lt;/h1&gt;

&lt;p&gt;You don’t always need:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Redis&lt;/li&gt;
&lt;li&gt;Kubernetes&lt;/li&gt;
&lt;li&gt;a service mesh&lt;/li&gt;
&lt;li&gt;a managed API gateway&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Sometimes you just need:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a well-placed filter&lt;/li&gt;
&lt;li&gt;an in-memory counter&lt;/li&gt;
&lt;li&gt;and the discipline to keep things simple.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I'm curious how other developers are dealing with this problem.&lt;/p&gt;

&lt;p&gt;Are bots hitting your APIs?&lt;/p&gt;

&lt;p&gt;And if so, how are you handling it?&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Redis rate limiting&lt;/li&gt;
&lt;li&gt;Cloudflare&lt;/li&gt;
&lt;li&gt;API Gateway&lt;/li&gt;
&lt;li&gt;something custom&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Would love to hear your experience.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>ai</category>
      <category>opensource</category>
      <category>security</category>
    </item>
  </channel>
</rss>
