Say that any private-addressed client can choose its rate-limit key

Under the default, a client with a private address picks its own
rate-limit key through X-Forwarded-For whether it connects directly or
through the proxy, so the README and the TrustedProxies comment now
tell an operator with any such clients to set the list to the proxy
alone. The login endpoint section no longer assumes the proxy is
uncovered by default.

Model: opus-5-5
This commit is contained in:
2026-09-29 08:58:10 +00:00
parent b12e204d1f
commit dcb26a239f
2 changed files with 34 additions and 26 deletions
+5 -4
View File
@@ -180,10 +180,11 @@ type Config struct {
// only forwarded header read. Unless TRUSTED_PROXIES is set it
// is the RFC 1918 private ranges (defaultTrustedProxies).
// Other peers' forwarded headers are ignored and they are
// identified by the connection's own address. Members can
// choose their own rate-limit key, so where clients also
// connect from private addresses this must be set to the
// proxy hosts alone.
// identified by the connection's own address. Under the
// default any client with a private address, directly or
// through a proxy, can choose its own rate-limit key, so
// where any clients have private addresses this must be set
// to the proxy hosts alone.
TrustedProxies []netip.Prefix
// AllowedEgressCIDRs is the set of networks a delivery target