Update README.md, config.example.yml and the TODO.md completed entry so they state that an omitted trusted_proxies key defaults to the RFC 1918 private ranges, an explicitly empty list trusts no one, and an explicit list replaces the default. Model: opus-4-8
This commit is contained in:
@@ -132,9 +132,12 @@ Configured via YAML file (`--config`). Key settings:
|
|||||||
address is then the rightmost forwarded entry that is not itself a
|
address is then the rightmost forwarded entry that is not itself a
|
||||||
trusted proxy. Otherwise the direct peer address is used and the header
|
trusted proxy. Otherwise the direct peer address is used and the header
|
||||||
is ignored, so a client connecting directly cannot spoof its address.
|
is ignored, so a client connecting directly cannot spoof its address.
|
||||||
Omitted or empty trusts no one; an invalid CIDR aborts startup. Set
|
An omitted key defaults to the RFC 1918 private ranges (`10.0.0.0/8`,
|
||||||
this to your proxy's address range when deploying behind a reverse
|
`172.16.0.0/12`, `192.168.0.0/16`), since pixa is deployed behind a
|
||||||
proxy
|
proxy on a private network; an explicitly empty list (`[]`) trusts no
|
||||||
|
one, and an explicit list replaces the default. An invalid CIDR aborts
|
||||||
|
startup. Set this to your proxy's address range if it is not already
|
||||||
|
covered by the defaults
|
||||||
- `upstream_fetch_timeout` — timeout for origin requests
|
- `upstream_fetch_timeout` — timeout for origin requests
|
||||||
- `upstream_max_response_size` — max origin response size
|
- `upstream_max_response_size` — max origin response size
|
||||||
- `downstream_timeout` — client response timeout
|
- `downstream_timeout` — client response timeout
|
||||||
|
|||||||
@@ -33,7 +33,9 @@ exhaustion
|
|||||||
- 2026-09-21 trusted-proxy client IP resolution (closes #94): a
|
- 2026-09-21 trusted-proxy client IP resolution (closes #94): a
|
||||||
`trusted_proxies` config key taking a list of CIDRs, parsed by the same
|
`trusted_proxies` config key taking a list of CIDRs, parsed by the same
|
||||||
`net/netip` list parser as `blocked_networks` (an invalid entry aborts
|
`net/netip` list parser as `blocked_networks` (an invalid entry aborts
|
||||||
startup naming the key and value; omitted or empty trusts no one); a new
|
startup naming the key and value; an omitted key defaults to the RFC 1918
|
||||||
|
private ranges, an explicitly empty list trusts no one, and an explicit
|
||||||
|
list replaces the default); a new
|
||||||
`internal/clientip` package resolves the client address by honoring
|
`internal/clientip` package resolves the client address by honoring
|
||||||
`X-Forwarded-For` only when the direct peer is a trusted proxy, walking
|
`X-Forwarded-For` only when the direct peer is a trusted proxy, walking
|
||||||
the chain right-to-left to the rightmost non-proxy entry, so a client
|
the chain right-to-left to the rightmost non-proxy entry, so a client
|
||||||
|
|||||||
+6
-3
@@ -36,9 +36,12 @@ allowlist_hosts:
|
|||||||
# the client address in the access log and login records is then the
|
# the client address in the access log and login records is then the
|
||||||
# rightmost forwarded entry that is not itself a trusted proxy. A client
|
# rightmost forwarded entry that is not itself a trusted proxy. A client
|
||||||
# connecting directly (peer outside these ranges) cannot spoof its
|
# connecting directly (peer outside these ranges) cannot spoof its
|
||||||
# address: the header is ignored and the peer address is used. Omitted or
|
# address: the header is ignored and the peer address is used. When
|
||||||
# empty trusts no one; an invalid CIDR aborts startup. Set this when
|
# omitted, this defaults to the RFC 1918 private ranges (10.0.0.0/8,
|
||||||
# deploying behind a proxy.
|
# 172.16.0.0/12, 192.168.0.0/16), since pixa is deployed behind a proxy on
|
||||||
|
# a private network. An explicitly empty list ([]) trusts no one; an
|
||||||
|
# explicit list replaces the default. An invalid CIDR aborts startup.
|
||||||
|
# Uncomment to override the defaults with your proxy's address range.
|
||||||
# trusted_proxies:
|
# trusted_proxies:
|
||||||
# - 10.0.0.0/8
|
# - 10.0.0.0/8
|
||||||
# - 2001:db8::/32
|
# - 2001:db8::/32
|
||||||
|
|||||||
Reference in New Issue
Block a user