Pin the rate-limit key for an empty RemoteAddr (closes #168)
check / check (push) Successful in 3m36s
check / check (push) Successful in 3m36s
A request with an empty RemoteAddr falls through to the raw-value fallback and keys on the empty string, so every such request shares one bucket. That is the fail-closed direction and stays as it is. A test now pins it, and the comment at the fallback tells it apart from the Unix-socket case. Model: opus-5-5
This commit is contained in:
@@ -219,7 +219,11 @@ func (m *Middleware) clientKey(r *http.Request) string {
|
||||
// path cannot silently collapse unrelated clients
|
||||
// together. On a Unix-socket listener every peer
|
||||
// carries the same RemoteAddr and so shares one bucket,
|
||||
// which is the fail-closed direction.
|
||||
// which is the fail-closed direction. An empty RemoteAddr
|
||||
// is a different case, which net/http never produces for
|
||||
// a TCP listener and only a hand-built request carries,
|
||||
// but it fails closed the same way: every such request
|
||||
// shares the one bucket keyed on the empty string.
|
||||
return r.RemoteAddr
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user