Correct trusted_proxies advice and state signature padding (closes #150)
check / check (push) Successful in 3m46s
check / check (push) Successful in 3m46s
The README told operators to set trusted_proxies to the proxy's own address. A proxy on the Docker host reaches pixa from the Docker network's gateway, so that advice made pixa count every user as one client for the login limit. The login-limit paragraph, the trusted_proxies entry and config.example.yml now say to use the address pixa sees for requests through the proxy, and how to read it from the request log. The signature section now says sig is base64url with the = padding kept, since pixa compares it exactly, and shows the example's sig for a stated key, computed with pixa's signer. Model: opus-5-5
This commit is contained in:
+6
-1
@@ -50,7 +50,12 @@ allowlist_hosts:
|
||||
# 172.16.0.0/12, 192.168.0.0/16), since pixa is deployed behind a proxy on
|
||||
# a private network. An explicitly empty list ([]) trusts no one; an
|
||||
# explicit list replaces the default. An invalid CIDR aborts startup.
|
||||
# Uncomment to override the defaults with your proxy's address range.
|
||||
# Uncomment to override the defaults with the address pixa sees for
|
||||
# requests that come through your proxy. That is not always the proxy's
|
||||
# own address: for a proxy on the Docker host it is the gateway of the
|
||||
# container's Docker network (172.17.0.1 on the default bridge). The
|
||||
# trusted_proxies entry in README.md says how to find it in the request
|
||||
# log.
|
||||
# trusted_proxies:
|
||||
# - 10.0.0.0/8
|
||||
# - 2001:db8::/32
|
||||
|
||||
Reference in New Issue
Block a user