Correct trusted_proxies advice and state signature padding (closes #150)
check / check (push) Successful in 14s
check / check (push) Successful in 14s
The README told operators to set trusted_proxies to the proxy's own address. A proxy on the Docker host that connects over 127.0.0.1 reaches pixa from the Docker network's gateway, so that advice made pixa count every user as one client for the login limit. The login-limit paragraph, the trusted_proxies entry and config.example.yml now say to use the address pixa sees for requests through the proxy, that a proxy connecting through another host address is seen with that address, and how to read it from the request log. The signature section now says sig is base64url with the = padding kept, since pixa compares it exactly, and shows the example's sig for a stated key, computed with pixa's signer. Model: opus-5-5
This commit was merged in pull request #153.
This commit is contained in:
@@ -30,6 +30,14 @@ exhaustion
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29 `trusted_proxies` advice and signature padding in `README.md`
|
||||
(closes #150): the login-limit paragraph, the `trusted_proxies` entry and
|
||||
`config.example.yml` say to set `trusted_proxies` to the address pixa sees for
|
||||
requests that come through the proxy, which the request log shows as
|
||||
`remoteIP` while it is not trusted; for a proxy on the Docker host that
|
||||
connects over `127.0.0.1` that is the Docker network's gateway, not the
|
||||
proxy's own address; the signature section says `sig` is base64url with the
|
||||
`=` padding kept, and gives the example's `sig` for a stated signing key.
|
||||
- 2026-09-29 fixed uid and gid for `pixad` (closes #151): the image creates the
|
||||
`pixad` group with gid 65532 and the `pixad` user with uid 65532, instead of
|
||||
the first free uid 1000, so a bind-mounted `/var/lib/pixa` given to `pixad`
|
||||
|
||||
Reference in New Issue
Block a user