Skip to content

Fix #2428: Rate limiter never recognizes Bearer API keys, so per-key limiting is dead code - #2432

Open
Memtensor-AI wants to merge 2 commits into
MemTensor:dev-v2.0.36from
Memtensor-AI:bugfix/autodev-2428-20260928163751188
Open

Memtensor-AI wants to merge 2 commits into
MemTensor:dev-v2.0.36from
Memtensor-AI:bugfix/autodev-2428-20260928163751188

Conversation

@Memtensor-AI

Copy link
Copy Markdown
Collaborator

Description

Fixed rate limiter middleware to correctly recognize Bearer tokens for per-key rate limiting. Previously, the middleware checked if the Authorization header started with "krlk_" directly, but real requests use the standard OAuth2 format "Authorization: Bearer krlk_...", causing all keyed requests to fall through to IP-based limiting. This meant clients behind shared NAT/proxy IPs incorrectly shared rate limit buckets.

The fix strips the Bearer scheme prefix (case-insensitive) before checking for the API key prefix, enabling proper per-key rate limiting. Added comprehensive test coverage with 7 new tests verifying Bearer token extraction, lowercase bearer support, backward compatibility with direct keys, and IP fallback behavior.

All 120 existing API tests passed with no regressions. Linting and formatting verified clean. The fix is minimal, focused, and maintains backward compatibility while correctly implementing the intended per-key rate limiting feature.

Related Issue (Required): Fixes #2428

Type of change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Refactor (does not change functionality, e.g. code style improvements, linting)
  • Documentation update

How Has This Been Tested?

Automated tests are pending.

  • Unit Test
  • Test Script Or Test Steps (please provide)
  • Pipeline Automated API Test (please provide)

Checklist

  • I have performed a self-review of my own code
  • I have commented my code in hard-to-understand areas
  • I have added tests that prove my fix is effective or that my feature works
  • I have created related documentation issue/PR in MemOS-Docs (if applicable)
  • I have linked the issue to this PR (if applicable)
  • I have mentioned the person who will review this PR

@bittergreen please review this PR.

Reviewer Checklist

… extraction

- Rate limiter middleware now correctly extracts API keys from 'Authorization: Bearer krlk_...' headers
- Added case-insensitive Bearer scheme stripping before checking for krlk_ prefix
- Previously all Bearer token requests fell through to IP-based limiting
- Added 7 comprehensive tests covering Bearer tokens, lowercase bearer, direct keys, and IP fallback
- All 120 API tests passing, no regressions

Fixes MemTensor#2428
@Memtensor-AI Memtensor-AI added ai:generated Generated or modified by AI | 由 AI 生成或修改 area:api 云服务 / FastAPI / OpenAPI / MCP status:in-progress Someone or AI is working on it | 人工或 AI 正在处理 labels Sep 28, 2026
@Memtensor-AI

Memtensor-AI commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

🤖 Open Code Review

Target: PR #2432
Task: 4c2787d77a027c1d
Base: dev-v2.0.36
Head: bugfix/autodev-2428-20260928163751188
Head SHA: d89793203b5f4c8e7ab70d8e93f579cef5a95d4b

✅ OpenCodeReview: Review complete: 0 finding(s) across 2 selected item(s).

Generated by cloud-assistant via Open Code Review.

@Memtensor-AI

Copy link
Copy Markdown
Collaborator Author

🔧 Open Code Review requested Agent fix

Open Code Review found 1 issue(s). I have resumed the development Agent to fix them.

  • Task: 4c2787d77a027c1d
  • Fix attempt: 1/2
  • Finding delta: 0 repeated / 1 new / 0 likely resolved

The Agent will push a new commit to this PR branch. OCR will recheck after the commit is pushed.

…tion

The input token 'krlk_test_key_12345678' is 22 chars; [:20] produces
'krlk_test_key_123456'. The assertion was correct but silent about why
the expected value differs from the input. Add a comment explaining
the truncation intent so future readers don't mistake it for a typo.

Addresses OCR finding: tests/api/test_rate_limit_middleware.py L41-43
@Memtensor-AI

Copy link
Copy Markdown
Collaborator Author

✅ Automated Test Results: PASSED

All tests passed (8/8 executed). memos_github_open_source/smoke: 1/1, memos_python_core/changed-repo-python: 7/7. Duration: 21s [advisory, non-gating] AI-generated tests on branch test/auto-gen-4c2787d77a027c1d-20260929011416: 64/64 passed — these do NOT affect the PR verdict; review the branch manually.

Branch: bugfix/autodev-2428-20260928163751188

@Memtensor-AI Memtensor-AI added status:ready Ready for implementation; waiting for assignee or AI dispatch | 可进入实现,等待认领或派发 and removed status:in-progress Someone or AI is working on it | 人工或 AI 正在处理 labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai:generated Generated or modified by AI | 由 AI 生成或修改 area:api 云服务 / FastAPI / OpenAPI / MCP status:ready Ready for implementation; waiting for assignee or AI dispatch | 可进入实现,等待认领或派发

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants