A request with an empty RemoteAddr cannot be read as an address, so the rate-limit key function falls back to the raw value and keys on the empty string: every such request shares one bucket across all four limiters. Following the plan on #168 (option 1), that behaviour stays as it is, since it fails closed and net/http never leaves RemoteAddr empty for a TCP listener.
A new test in internal/middleware/ratelimit_test.go pins it: an empty RemoteAddr keys on the empty string.
The comment at the fallback in clientKey now says the empty case is distinct from the Unix-socket case (only a hand-built request carries it) but fails closed the same way.
No behaviour change.
Model: opus-5-5
A request with an empty `RemoteAddr` cannot be read as an address, so the rate-limit key function falls back to the raw value and keys on the empty string: every such request shares one bucket across all four limiters. Following the plan on https://git.eeqj.de/sneak/webhooker/issues/168 (option 1), that behaviour stays as it is, since it fails closed and `net/http` never leaves `RemoteAddr` empty for a TCP listener.
- A new test in `internal/middleware/ratelimit_test.go` pins it: an empty `RemoteAddr` keys on the empty string.
- The comment at the fallback in `clientKey` now says the empty case is distinct from the Unix-socket case (only a hand-built request carries it) but fails closed the same way.
No behaviour change.
Model: opus-5-5
A request with an empty RemoteAddr falls through to the raw-value
fallback and keys on the empty string, so every such request shares
one bucket. That is the fail-closed direction and stays as it is. A
test now pins it, and the comment at the fallback tells it apart from
the Unix-socket case.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A request with an empty
RemoteAddrcannot be read as an address, so the rate-limit key function falls back to the raw value and keys on the empty string: every such request shares one bucket across all four limiters. Following the plan on #168 (option 1), that behaviour stays as it is, since it fails closed andnet/httpnever leavesRemoteAddrempty for a TCP listener.internal/middleware/ratelimit_test.gopins it: an emptyRemoteAddrkeys on the empty string.clientKeynow says the empty case is distinct from the Unix-socket case (only a hand-built request carries it) but fails closed the same way.No behaviour change.
Model: opus-5-5
Review passed.
Model: opus-5-5