#280: remove PALETTE_TRUSTED_IP_HEADER, key rate limits on peer address only
Owner follow-up to the #280 fix (PR #284): the trusted-header env var is gone. clientIP() now uses the peer address exclusively and ignores all client-supplied IP headers; the env var row is removed from the README.
This commit is contained in:
@@ -7,8 +7,6 @@ import (
|
||||
)
|
||||
|
||||
func TestClientIPUsesRemoteAddrNotXFF(t *testing.T) {
|
||||
SetTrustedIPHeader("")
|
||||
defer SetTrustedIPHeader("")
|
||||
r := httptest.NewRequest("POST", "/api/pastes", nil)
|
||||
r.RemoteAddr = "203.0.113.7:4432"
|
||||
r.Header.Set("X-Forwarded-For", "1.2.3.4, 1.2.3.5, 203.0.113.9")
|
||||
@@ -18,18 +16,15 @@ func TestClientIPUsesRemoteAddrNotXFF(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientIPTrustedHeaderOnlyWhenConfigured(t *testing.T) {
|
||||
SetTrustedIPHeader("")
|
||||
defer SetTrustedIPHeader("")
|
||||
// A proxy-controlled header is not honored even when set: #280 revision
|
||||
// removed the PALETTE_TRUSTED_IP_HEADER mechanism per owner decision, so the
|
||||
// bucket key is the peer address only.
|
||||
func TestClientIPNeverTrustsHeaders(t *testing.T) {
|
||||
r := httptest.NewRequest("POST", "/api/pastes", nil)
|
||||
r.RemoteAddr = "10.0.1.47:9999"
|
||||
r.Header.Set("CF-Connecting-IP", "198.51.100.9")
|
||||
if got := clientIP(r); got != "10.0.1.47" {
|
||||
t.Fatalf("unconfigured: clientIP = %q, want peer 10.0.1.47", got)
|
||||
}
|
||||
SetTrustedIPHeader("CF-Connecting-IP")
|
||||
if got := clientIP(r); got != "198.51.100.9" {
|
||||
t.Fatalf("configured: clientIP = %q, want CF-Connecting-IP value", got)
|
||||
t.Fatalf("clientIP = %q, want peer 10.0.1.47", got)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -37,9 +32,7 @@ func TestClientIPTrustedHeaderOnlyWhenConfigured(t *testing.T) {
|
||||
// repro was 8 creates with rotating XFF -> 6x201.
|
||||
func TestRotatingXFFDoesNotResetBucket(t *testing.T) {
|
||||
globalLimiter = newLimiter()
|
||||
defer SetTrustedIPHeader("")
|
||||
SetTrustedIPHeader("")
|
||||
s := defaultSettings(Config{}) // burst/limit defaults; any header values are ignored anyway
|
||||
s := defaultSettings(Config{}) // burst/limit defaults; header values are ignored anyway
|
||||
var allowed, limited int
|
||||
for i := 0; i < 8; i++ {
|
||||
r := httptest.NewRequest("POST", "/api/pastes", nil)
|
||||
|
||||
Reference in New Issue
Block a user