middleware: take the client address from the right of X-Forwarded-For (closes #181)
check / check (push) Successful in 1m22s
check / check (push) Successful in 1m22s
realIP took the first X-Forwarded-For entry, which the client itself can write, so behind a proxy that appends to the header a client chose the address dnswatcher logs and the /metrics rate limit counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one; the leftmost when all are. All X-Forwarded-For header lines are read as one list, since a proxy may add its own line instead of appending to the client's. An empty entry where the client address belongs falls back to the peer address, as an empty first entry did before. X-Real-IP is unchanged. Model: opus-5-5
This commit was merged in pull request #183.
This commit is contained in:
@@ -347,9 +347,9 @@ minute, failed logins included; beyond that it answers `429 Too Many Requests`
|
||||
without checking the password. A Prometheus server scraping every 15 seconds
|
||||
sends 4 a minute. IPv6 addresses in one /64 count as one client. When the
|
||||
request comes from a private or loopback address, such as a reverse proxy's,
|
||||
the client address is taken from the `X-Real-IP` or `X-Forwarded-For` header
|
||||
the proxy sets; a proxy that sets neither makes all its clients share one
|
||||
allowance.
|
||||
the client address is taken from the `X-Real-IP` header the proxy sets, or else
|
||||
from `X-Forwarded-For`, as the last address in it that is not private or
|
||||
loopback. A proxy that sets neither makes all its clients share one allowance.
|
||||
|
||||
**`DNSWATCHER_DNS_INTERVAL` and `DNSWATCHER_TLS_INTERVAL`** take a positive
|
||||
duration: a number followed by a unit such as `s`, `m` or `h`, for example
|
||||
|
||||
Reference in New Issue
Block a user