check / check (push) Successful in 50s
nginx trusted X-Forwarded-For from every RFC1918 address, so a client reaching it from one could write a new address on each request and get a fresh rate-limit allowance. The container's TRUSTED_PROXIES now names the reverse proxies nginx trusts, none by default. bin/entrypoint.sh makes each entry a CIDR, checks it with the new "netwatch-server check-cidr", which runs the server's own TRUSTED_PROXIES parsing, and writes one set_real_ip_from line per entry into /etc/nginx/trusted-proxies.conf, which nginx.conf includes. The backend is started with TRUSTED_PROXIES=127.0.0.1/32, since nginx is its only client. The viewport test mounts an empty file there. Model: opus-5-5
32 lines
788 B
Go
32 lines
788 B
Go
package middleware
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
"net/netip"
|
|
)
|
|
|
|
// Test-only wrappers exposing unexported helpers to the
|
|
// external middleware_test package.
|
|
|
|
// NewWithLogger builds a Middleware around a logger for tests
|
|
// that exercise the logging paths without the fx graph.
|
|
func NewWithLogger(log *slog.Logger) *Middleware {
|
|
return &Middleware{log: log}
|
|
}
|
|
|
|
// NewWithTrustedProxies builds a Middleware that honours forwarded
|
|
// headers from the given networks, for tests of the client address
|
|
// paths without the fx graph.
|
|
func NewWithTrustedProxies(trusted []netip.Prefix) *Middleware {
|
|
return &Middleware{trustedProxies: trusted}
|
|
}
|
|
|
|
func ClientIP(
|
|
remoteAddr string,
|
|
header http.Header,
|
|
trusted []netip.Prefix,
|
|
) string {
|
|
return clientIP(remoteAddr, header, trusted)
|
|
}
|