the door being limited, part of each bucket's key
the express request, for the address
Optionalidentity: unknown
optional; the identity attempted
Optionallimit: NamedLimit
optional; a ceiling for both buckets, or
{ identity, address }, overriding the settings
{ ok: true }, or { ok: false, kind, limit, retryAfterS, detail }
Counts one attempt in this process's buckets and says whether it is allowed.
Two buckets are counted, by identity (when one is given) and by address, in a fixed window of
security.rateLimitWindowS. A refusal is logged and names the bucket that refused.