nginx: trust X-Forwarded-For only from TRUSTED_PROXIES (closes #64)
check / check (push) Successful in 50s
check / check (push) Successful in 50s
nginx trusted X-Forwarded-For from every RFC1918 address, so a client reaching it from one could write a new address on each request and get a fresh rate-limit allowance. The container's TRUSTED_PROXIES now names the reverse proxies nginx trusts, none by default. bin/entrypoint.sh makes each entry a CIDR, checks it with the new "netwatch-server check-cidr", which runs the server's own TRUSTED_PROXIES parsing, and writes one set_real_ip_from line per entry into /etc/nginx/trusted-proxies.conf, which nginx.conf includes. The backend is started with TRUSTED_PROXIES=127.0.0.1/32, since nginx is its only client. The viewport test mounts an empty file there. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,15 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: nginx takes the client address from `X-Forwarded-For` only on
|
||||
requests from the reverse proxies named in the container's `TRUSTED_PROXIES`
|
||||
(issue #64), and by default from none, where it trusted every RFC1918 address
|
||||
before, so a client could write a new address on each request and escape the
|
||||
rate limit. `bin/entrypoint.sh` writes one `set_real_ip_from` line per entry
|
||||
into `/etc/nginx/trusted-proxies.conf`, which `nginx.conf` includes, refusing
|
||||
an entry that is not an IP address or CIDR, as `netwatch-server check-cidr`
|
||||
finds; it starts the backend with `TRUSTED_PROXIES=127.0.0.1/32`, since nginx
|
||||
is its only client
|
||||
- 2026-09-29: ready to run under upaas (issue #59): the image has a
|
||||
`HEALTHCHECK` that requests `/.well-known/healthcheck` through nginx on the
|
||||
port from `PORT`. The backend no longer reads a bad `PORT` as 0 or a bad
|
||||
|
||||
Reference in New Issue
Block a user