Key the TRUSTED_PROXIES rule to the source address seen on arrival
check / check (push) Successful in 4m41s

The README and the TrustedProxies comment now say, once per passage,
that the list must be set to the proxy's address alone if any client
can reach webhooker or the proxy from an RFC 1918 source address,
directly or through anything that can rewrite source addresses, and
that the address to set is the remoteIP field of the http request log
line. The loopback case in the reverse-proxy checklist is now a proxy
reaching the binary bound to 127.0.0.1. Other sentences about which
clients can choose their own rate-limit key are cut.

Model: opus-5-5
This commit is contained in:
2026-10-01 21:19:34 +00:00
parent 98f719ded3
commit 03b19c48e9
2 changed files with 52 additions and 76 deletions
+7 -7
View File
@@ -178,13 +178,13 @@ type Config struct {
// TrustedProxies is the set of networks whose members are
// allowed to speak for the client with X-Forwarded-For, the
// only forwarded header read. Unless TRUSTED_PROXIES is set it
// is the RFC 1918 private ranges (defaultTrustedProxies).
// Other peers' forwarded headers are ignored and they are
// identified by the connection's own address. Under the
// default any client with a private address, directly or
// through a trusted proxy, can choose its own rate-limit
// key, so where any clients have private addresses this must
// be set to the proxy hosts alone.
// is the RFC 1918 private ranges (defaultTrustedProxies); a set
// value replaces them. If any client can reach the process, or
// the proxy in front of it, from an RFC 1918 source address
// (directly, or through anything that can rewrite source
// addresses, such as NAT or a published container port), it
// must be set to the proxy's address alone, or every rate limit
// can be bypassed by those clients.
TrustedProxies []netip.Prefix
// AllowedEgressCIDRs is the set of networks a delivery target