Correct trusted_proxies advice and state signature padding (closes #150)
check / check (push) Successful in 3m46s

The README told operators to set trusted_proxies to the proxy's own
address. A proxy on the Docker host reaches pixa from the Docker
network's gateway, so that advice made pixa count every user as one
client for the login limit. The login-limit paragraph, the
trusted_proxies entry and config.example.yml now say to use the address
pixa sees for requests through the proxy, and how to read it from the
request log.

The signature section now says sig is base64url with the = padding
kept, since pixa compares it exactly, and shows the example's sig for a
stated key, computed with pixa's signer.

Model: opus-5-5
This commit is contained in:
2026-09-29 02:50:45 +00:00
parent ed3f8770e6
commit cb8c885061
3 changed files with 49 additions and 17 deletions
+8
View File
@@ -30,6 +30,14 @@ exhaustion
# Completed Steps
- 2026-09-29 `trusted_proxies` advice and signature padding in `README.md`
(closes #150): the login-limit paragraph, the `trusted_proxies` entry and
`config.example.yml` say to set `trusted_proxies` to the address pixa sees for
requests that come through the proxy, not the proxy's own address; for a proxy
on the Docker host that is the Docker network's gateway, which the request log
shows as `remoteIP` while it is not trusted; the signature section says `sig`
is base64url with the `=` padding kept, and gives the example's `sig` for a
stated signing key.
- 2026-09-29 fixed uid and gid for `pixad` (closes #151): the image creates the
`pixad` group with gid 65532 and the `pixad` user with uid 65532, instead of
the first free uid 1000, so a bind-mounted `/var/lib/pixa` given to `pixad`