middleware: take the client address from the right of X-Forwarded-For (closes #181)
check / check (push) Successful in 1m22s
check / check (push) Successful in 1m22s
realIP took the first X-Forwarded-For entry, which the client itself can write, so behind a proxy that appends to the header a client chose the address dnswatcher logs and the /metrics rate limit counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one; the leftmost when all are. All X-Forwarded-For header lines are read as one list, since a proxy may add its own line instead of appending to the client's. An empty entry where the client address belongs falls back to the peer address, as an empty first entry did before. X-Real-IP is unchanged. Model: opus-5-5
This commit was merged in pull request #183.
This commit is contained in:
@@ -19,6 +19,8 @@ nameserver IP address changes: https://git.eeqj.de/sneak/dnswatcher/issues/105
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-01: the client address from `X-Forwarded-For` is the last entry that
|
||||
is not a trusted proxy, not the first, which the client sets (closes #181).
|
||||
- 2026-10-01: a nameserver that does not answer is saved as `error` with the
|
||||
reason, and NS failure and NS recovery are notified (closes #104).
|
||||
- 2026-10-01: a `DNSWATCHER_DNS_INTERVAL` or `DNSWATCHER_TLS_INTERVAL` that is
|
||||
|
||||
Reference in New Issue
Block a user