middleware: take the client address from the right of X-Forwarded-For (closes #181) #183

Merged
clawbot merged 1 commits from issue-181-xff-client into next 2026-10-01 22:35:18 +02:00
Collaborator

Closes #181.

realIP took the first X-Forwarded-For entry. A proxy appends to the header the client sent, so the client chose that entry, and with it the address dnswatcher logs and the /metrics rate limit from #180 counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one, or the leftmost when all are. X-Real-IP still wins over X-Forwarded-For and is otherwise unchanged; from a peer that is not a trusted proxy both headers are still ignored.

Not visible in the diff:

  • The rate limit tests from #180 send only X-Real-IP, so they still test what they say. The address constants they use now also serve the new TestRealIP, and their comment says so.
  • A client on a private network behind the proxy is itself a trusted address, so the walk continues into entries that client wrote. That follows from the rule in the issue.

Judgement calls:

  • All X-Forwarded-For header lines are read as one list. A proxy that adds its own line instead of appending would otherwise leave the client's line first, the same hole.
  • An empty entry where the client address belongs gives the peer address, as an empty first entry did before.

The README's /metrics rate limit paragraph now says how the address is read from X-Forwarded-For.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/dnswatcher/issues/181. `realIP` took the first `X-Forwarded-For` entry. A proxy appends to the header the client sent, so the client chose that entry, and with it the address dnswatcher logs and the `/metrics` rate limit from https://git.eeqj.de/sneak/dnswatcher/pulls/180 counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one, or the leftmost when all are. `X-Real-IP` still wins over `X-Forwarded-For` and is otherwise unchanged; from a peer that is not a trusted proxy both headers are still ignored. Not visible in the diff: - The rate limit tests from https://git.eeqj.de/sneak/dnswatcher/pulls/180 send only `X-Real-IP`, so they still test what they say. The address constants they use now also serve the new `TestRealIP`, and their comment says so. - A client on a private network behind the proxy is itself a trusted address, so the walk continues into entries that client wrote. That follows from the rule in the issue. Judgement calls: - All `X-Forwarded-For` header lines are read as one list. A proxy that adds its own line instead of appending would otherwise leave the client's line first, the same hole. - An empty entry where the client address belongs gives the peer address, as an empty first entry did before. The README's `/metrics` rate limit paragraph now says how the address is read from `X-Forwarded-For`. Model: opus-5-5
clawbot added the needs-review label 2026-10-01 22:22:27 +02:00
clawbot self-assigned this 2026-10-01 22:22:27 +02:00
Author
Collaborator

Review passed on a41ff44.

Model: opus-5-5

Review passed on a41ff44. Model: opus-5-5
clawbot added 1 commit 2026-10-01 22:34:39 +02:00
realIP took the first X-Forwarded-For entry, which the client itself
can write, so behind a proxy that appends to the header a client chose
the address dnswatcher logs and the /metrics rate limit counts. It now
walks the entries from the right past trusted proxies, using the
existing trusted-proxy check, and takes the first that is not one; the
leftmost when all are. All X-Forwarded-For header lines are read as one
list, since a proxy may add its own line instead of appending to the
client's. An empty entry where the client address belongs falls back
to the peer address, as an empty first entry did before. X-Real-IP is
unchanged.

Model: opus-5-5
clawbot force-pushed issue-181-xff-client from a41ff44b16 to 4d1d172afd 2026-10-01 22:34:39 +02:00 Compare
clawbot merged commit a8f9a64600 into next 2026-10-01 22:35:18 +02:00
clawbot deleted branch issue-181-xff-client 2026-10-01 22:35:18 +02:00
clawbot removed the needs-review label 2026-10-01 22:35:18 +02:00
Sign in to join this conversation.