Key the TRUSTED_PROXIES rule to the source address seen on arrival
check / check (push) Successful in 4m37s
check / check (push) Successful in 4m37s
The README and the TrustedProxies comment now say, once per passage, that the list must be set to the proxy's address alone if any client can reach webhooker or the proxy from an RFC 1918 source address, directly or through anything that can rewrite source addresses, and that the address to set is the remoteIP field of the http request log line. The loopback case in the reverse-proxy checklist is now a proxy reaching the binary bound to 127.0.0.1. Other sentences about which clients can choose their own rate-limit key are cut. Model: opus-5-5
This commit is contained in:
@@ -178,13 +178,13 @@ type Config struct {
|
||||
// TrustedProxies is the set of networks whose members are
|
||||
// allowed to speak for the client with X-Forwarded-For, the
|
||||
// only forwarded header read. Unless TRUSTED_PROXIES is set it
|
||||
// is the RFC 1918 private ranges (defaultTrustedProxies).
|
||||
// Other peers' forwarded headers are ignored and they are
|
||||
// identified by the connection's own address. Under the
|
||||
// default any client with a private address, directly or
|
||||
// through a trusted proxy, can choose its own rate-limit
|
||||
// key, so where any clients have private addresses this must
|
||||
// be set to the proxy hosts alone.
|
||||
// is the RFC 1918 private ranges (defaultTrustedProxies); a set
|
||||
// value replaces them. If any client can reach the process, or
|
||||
// the proxy in front of it, from an RFC 1918 source address
|
||||
// (directly, or through anything that can rewrite source
|
||||
// addresses, such as NAT or a published container port), it
|
||||
// must be set to the proxy's address alone, or every rate limit
|
||||
// can be bypassed by those clients.
|
||||
TrustedProxies []netip.Prefix
|
||||
|
||||
// AllowedEgressCIDRs is the set of networks a delivery target
|
||||
|
||||
Reference in New Issue
Block a user