check / check (push) Successful in 2m33s
A proxy on a dual-stack listener forwards an IPv4 client as ::ffff:a.b.c.d, whose /64 is the same for every IPv4 client, so one client's failed logins refused everyone's. The rate limit key now unmaps the address first. README.md now says that with the default trusted_proxies a client with a private address can choose its counted address through X-Forwarded-For, and that setting trusted_proxies to the proxy's own address closes this. Model: opus-5-5