realIP took the first X-Forwarded-For entry. A proxy appends to the header the client sent, so the client chose that entry, and with it the address dnswatcher logs and the /metrics rate limit from #180 counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one, or the leftmost when all are. X-Real-IP still wins over X-Forwarded-For and is otherwise unchanged; from a peer that is not a trusted proxy both headers are still ignored.
Not visible in the diff:
The rate limit tests from #180 send only X-Real-IP, so they still test what they say. The address constants they use now also serve the new TestRealIP, and their comment says so.
A client on a private network behind the proxy is itself a trusted address, so the walk continues into entries that client wrote. That follows from the rule in the issue.
Judgement calls:
All X-Forwarded-For header lines are read as one list. A proxy that adds its own line instead of appending would otherwise leave the client's line first, the same hole.
An empty entry where the client address belongs gives the peer address, as an empty first entry did before.
The README's /metrics rate limit paragraph now says how the address is read from X-Forwarded-For.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/dnswatcher/issues/181.
`realIP` took the first `X-Forwarded-For` entry. A proxy appends to the header the client sent, so the client chose that entry, and with it the address dnswatcher logs and the `/metrics` rate limit from https://git.eeqj.de/sneak/dnswatcher/pulls/180 counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one, or the leftmost when all are. `X-Real-IP` still wins over `X-Forwarded-For` and is otherwise unchanged; from a peer that is not a trusted proxy both headers are still ignored.
Not visible in the diff:
- The rate limit tests from https://git.eeqj.de/sneak/dnswatcher/pulls/180 send only `X-Real-IP`, so they still test what they say. The address constants they use now also serve the new `TestRealIP`, and their comment says so.
- A client on a private network behind the proxy is itself a trusted address, so the walk continues into entries that client wrote. That follows from the rule in the issue.
Judgement calls:
- All `X-Forwarded-For` header lines are read as one list. A proxy that adds its own line instead of appending would otherwise leave the client's line first, the same hole.
- An empty entry where the client address belongs gives the peer address, as an empty first entry did before.
The README's `/metrics` rate limit paragraph now says how the address is read from `X-Forwarded-For`.
Model: opus-5-5
realIP took the first X-Forwarded-For entry, which the client itself
can write, so behind a proxy that appends to the header a client chose
the address dnswatcher logs and the /metrics rate limit counts. It now
walks the entries from the right past trusted proxies, using the
existing trusted-proxy check, and takes the first that is not one; the
leftmost when all are. All X-Forwarded-For header lines are read as one
list, since a proxy may add its own line instead of appending to the
client's. An empty entry where the client address belongs falls back
to the peer address, as an empty first entry did before. X-Real-IP is
unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #181.
realIPtook the firstX-Forwarded-Forentry. A proxy appends to the header the client sent, so the client chose that entry, and with it the address dnswatcher logs and the/metricsrate limit from #180 counts. It now walks the entries from the right past trusted proxies, using the existing trusted-proxy check, and takes the first that is not one, or the leftmost when all are.X-Real-IPstill wins overX-Forwarded-Forand is otherwise unchanged; from a peer that is not a trusted proxy both headers are still ignored.Not visible in the diff:
X-Real-IP, so they still test what they say. The address constants they use now also serve the newTestRealIP, and their comment says so.Judgement calls:
X-Forwarded-Forheader lines are read as one list. A proxy that adds its own line instead of appending would otherwise leave the client's line first, the same hole.The README's
/metricsrate limit paragraph now says how the address is read fromX-Forwarded-For.Model: opus-5-5
Review passed on
a41ff44.Model: opus-5-5
a41ff44b16to4d1d172afd