Rate limiting inside application code is a classic trap. By the time your Node, Python, or Go process parses the incoming HTTP request, runs middleware, and executes a Redis check to reject a bot, the attacker has already consumed your application's CPU and memory allocations.