diff --git a/internal/server/login_rate_limit_internal_test.go b/internal/server/login_rate_limit_internal_test.go index 721f148..13195c0 100644 --- a/internal/server/login_rate_limit_internal_test.go +++ b/internal/server/login_rate_limit_internal_test.go @@ -260,3 +260,21 @@ func TestLoginRateLimitCountsIPv6ClientsByPrefix(t *testing.T) { rec.Code, http.StatusOK) } } + +// TestLoginRateLimitCountsIPv4MappedClientsSeparately verifies an IPv4 +// client that the proxy forwards in IPv4-mapped IPv6 form (::ffff:a.b.c.d) +// is counted by its IPv4 address, not by the /64 that every such address +// shares, so two of them behind the proxy are counted separately. +func TestLoginRateLimitCountsIPv4MappedClientsSeparately(t *testing.T) { + t.Parallel() + + s := newTestServer(t) + + tripLoginRateLimit(t, s, proxyPeer, "::ffff:"+firstForwarded) + + rec := postLogin(t, s, proxyPeer, "::ffff:"+secondForwarded, wrongKey) + if rec.Code != http.StatusOK { + t.Errorf("failed login from a second IPv4-mapped client "+ + "status = %d, want %d", rec.Code, http.StatusOK) + } +}