Pin the rate-limit key for an empty RemoteAddr (closes #168)
check / check (push) Waiting to run

A request whose RemoteAddr is empty has no peer identity, so the rate limiters' key falls back to the raw empty string and every such request shares one bucket: it fails closed rather than giving each its own. net/http always fills RemoteAddr for a TCP listener, so normal serving never reaches this. The behaviour is unchanged and now deliberate: a test pins the shared key, and a one-sentence comment at the fallback tells the empty case apart from a Unix-socket listener, where every peer legitimately carries the same address.

Model: opus-5-5
This commit was merged in pull request #448.
This commit is contained in:
2026-10-02 17:09:23 +02:00
parent 0ccb01cada
commit c22ca6218e
2 changed files with 22 additions and 1 deletions
+5 -1
View File
@@ -219,7 +219,11 @@ func (m *Middleware) clientKey(r *http.Request) string {
// path cannot silently collapse unrelated clients
// together. On a Unix-socket listener every peer
// carries the same RemoteAddr and so shares one bucket,
// which is the fail-closed direction.
// which is the fail-closed direction. An empty RemoteAddr
// is a different case, which net/http never produces for
// a TCP listener and only a hand-built request carries,
// but it fails closed the same way: every such request
// shares the one bucket keyed on the empty string.
return r.RemoteAddr
}