fix: loginLimiter.allow returns true (no rate limit) for empty IP #31
Labels
No labels
backend
bug
chore
duplication
effort:complex
effort:medium
effort:trivial
enhancement
follow-up
frontend
fullstack
priority:high
ready-for-agent
refactor
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
dries/ocman#31
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
internal/server/auth.go:328-331:clientIP()falls back to the rawr.RemoteAddrstring whennet.SplitHostPortfails, so reachingip == ""requiresr.RemoteAddritself to be empty — which the standardnet/httpserver never produces. However:gui.RunGUI, which may use a different listener type in the future.r.RemoteAddr = "".X-Forwarded-Forstripping could arrive here as empty.Returning
trueon empty IP silently bypasses the rate limiter entirely, turning every empty-IP source into an unlimited login attempt endpoint.Suggested fix
Return
false(deny) on empty IP, or use a synthetic sentinel bucket key so the rate limit still applies:This is conservative: a legitimate browser will always have a RemoteAddr, so an empty IP is almost certainly an infrastructure anomaly that shouldn't get a free pass.
References
internal/server/auth.go:328-331internal/server/auth.go:357-367(clientIP()— fallback path)