Bug Description
_get_client_key in src/memos/api/middleware/rate_limit.py tries to rate-limit by API key when the Authorization header starts with krlk_:
auth_header = request.headers.get("Authorization", "")
if auth_header.startswith("krlk_"):
return f"ratelimit:key:{auth_header[:20]}"
Real requests send Authorization: Bearer krlk_..., so the header never starts with krlk_ and this branch is unreachable. Every request — including ones carrying a valid API key — falls through to IP-based limiting, and behind a shared egress IP all keyed clients share one bucket.
Expected Behavior
Strip the Bearer scheme before checking the key prefix, so keyed requests get a per-key rate-limit bucket.
Environment
MemOS main, python 3.14.
Additional Context
Fix + red/green-verified tests ready; PR to follow referencing this issue.
Bug Description
_get_client_keyinsrc/memos/api/middleware/rate_limit.pytries to rate-limit by API key when theAuthorizationheader starts withkrlk_:Real requests send
Authorization: Bearer krlk_..., so the header never starts withkrlk_and this branch is unreachable. Every request — including ones carrying a valid API key — falls through to IP-based limiting, and behind a shared egress IP all keyed clients share one bucket.Expected Behavior
Strip the
Bearerscheme before checking the key prefix, so keyed requests get a per-key rate-limit bucket.Environment
MemOS main, python 3.14.
Additional Context
Fix + red/green-verified tests ready; PR to follow referencing this issue.