Test that IPv4-mapped login clients are counted apart (closes #66)
check / check (push) Failing after 1m51s

Two IPv4 clients that the trusted proxy forwards in IPv4-mapped form must
not share one login count. Fails: both fall in the same /64.

Model: opus-5-5
This commit is contained in:
2026-09-28 22:48:12 +00:00
parent e6c326fc96
commit 39051ee4a3
@@ -260,3 +260,21 @@ func TestLoginRateLimitCountsIPv6ClientsByPrefix(t *testing.T) {
rec.Code, http.StatusOK) rec.Code, http.StatusOK)
} }
} }
// TestLoginRateLimitCountsIPv4MappedClientsSeparately verifies an IPv4
// client that the proxy forwards in IPv4-mapped IPv6 form (::ffff:a.b.c.d)
// is counted by its IPv4 address, not by the /64 that every such address
// shares, so two of them behind the proxy are counted separately.
func TestLoginRateLimitCountsIPv4MappedClientsSeparately(t *testing.T) {
t.Parallel()
s := newTestServer(t)
tripLoginRateLimit(t, s, proxyPeer, "::ffff:"+firstForwarded)
rec := postLogin(t, s, proxyPeer, "::ffff:"+secondForwarded, wrongKey)
if rec.Code != http.StatusOK {
t.Errorf("failed login from a second IPv4-mapped client "+
"status = %d, want %d", rec.Code, http.StatusOK)
}
}