rate-limit
Technical notes on web development, DevOps, and AI integration.
2 articles
- 04:27testing
Testing a Go Rate Limiter Without Waiting for Real Time
Swap the clock in Go tests: a rate limiter proven without sleep, plus when to graduate to testing/synctest.
TL;DR: Rate limiter tests shouldn't chase real time with time.Sleep, which makes them slow and flaky. Instead, expose a Now func() time.Time field on the struct and swap in a fixed clock, letting tests advance time instantly with no sleeps. For code that sleeps internally, Go's stable testing/synctest bubble fakes the clock.
#go#testing#rate-limit - 04:43backend
The Client IP You Can Actually Trust
The first X-Forwarded-For entry is attacker-controlled. Which address behind Cloudflare and nginx actually deserves a rate limiter's trust.
TL;DR: A burst of password guesses on an admin login exposed a flaw: the rate limiter trusted an attacker-controlled X-Forwarded-For entry. The fix prefers Cloudflare's CF-Connecting-IP header, then the last proxy entry, then X-Real-IP, and finally the raw connection address. Per-account keys pairing IP with email, 429 responses with Retry-After, and bounded memory keep the limiter effective.
#go#security#nginx