Files
netwatch/script
clawbot 02dbd1a89b
check / check (push) Successful in 50s
nginx: trust X-Forwarded-For only from TRUSTED_PROXIES (closes #64)
nginx trusted X-Forwarded-For from every RFC1918 address, so a client
reaching it from one could write a new address on each request and
get a fresh rate-limit allowance. The container's TRUSTED_PROXIES now
names the reverse proxies nginx trusts, none by default.
bin/entrypoint.sh makes each entry a CIDR, checks it with the new
"netwatch-server check-cidr", which runs the server's own
TRUSTED_PROXIES parsing, and writes one set_real_ip_from line per
entry into /etc/nginx/trusted-proxies.conf, which nginx.conf includes.
The backend is started with TRUSTED_PROXIES=127.0.0.1/32, since nginx
is its only client. The viewport test mounts an empty file there.

Model: opus-5-5
2026-09-29 05:48:43 +00:00
..
2026-07-07 02:14:16 +02:00
2026-07-07 02:14:16 +02:00
2026-07-07 02:14:16 +02:00
2026-07-07 02:14:16 +02:00