Name every rate limit that shares the client key

"Trusted proxies" now says a block covering clients makes every rate
limit bypassable, not "all three"; Rate Limiting lists delivery replay
and event resubmit among the limiters sharing the key. The
Configuration table and the TrustedProxies comment say a private
client behind a trusted proxy chooses its key, not behind any proxy.

Model: opus-5-5
This commit is contained in:
2026-10-01 21:13:28 +00:00
parent 0da5f26bdf
commit 98f719ded3
2 changed files with 12 additions and 12 deletions
+3 -3
View File
@@ -182,9 +182,9 @@ type Config struct {
// Other peers' forwarded headers are ignored and they are
// identified by the connection's own address. Under the
// default any client with a private address, directly or
// through a proxy, can choose its own rate-limit key, so
// where any clients have private addresses this must be set
// to the proxy hosts alone.
// through a trusted proxy, can choose its own rate-limit
// key, so where any clients have private addresses this must
// be set to the proxy hosts alone.
TrustedProxies []netip.Prefix
// AllowedEgressCIDRs is the set of networks a delivery target