middleware: take the client address from the right of X-Forwarded-For (closes #181) #183

Merged
clawbot merged 1 commits from issue-181-xff-client into next 2026-10-01 22:35:18 +02:00
1 Commits
Author SHA1 Message Date
sneak 4d1d172afd middleware: take the client address from the right of X-Forwarded-For (closes #181)
check / check (push) Successful in 1m42s
realIP took the first X-Forwarded-For entry, which the client itself
can write, so behind a proxy that appends to the header a client chose
the address dnswatcher logs and the /metrics rate limit counts. It now
walks the entries from the right past trusted proxies, using the
existing trusted-proxy check, and takes the first that is not one; the
leftmost when all are. All X-Forwarded-For header lines are read as one
list, since a proxy may add its own line instead of appending to the
client's. An empty entry where the client address belongs falls back
to the peer address, as an empty first entry did before. X-Real-IP is
unchanged.

Model: opus-5-5
2026-10-01 20:33:54 +00:00