Say that any private-addressed client can choose its rate-limit key
Under the default, a client with a private address picks its own rate-limit key through X-Forwarded-For whether it connects directly or through the proxy, so the README and the TrustedProxies comment now tell an operator with any such clients to set the list to the proxy alone. The login endpoint section no longer assumes the proxy is uncovered by default. Model: opus-5-5
This commit is contained in:
@@ -180,10 +180,11 @@ type Config struct {
|
||||
// only forwarded header read. Unless TRUSTED_PROXIES is set it
|
||||
// is the RFC 1918 private ranges (defaultTrustedProxies).
|
||||
// Other peers' forwarded headers are ignored and they are
|
||||
// identified by the connection's own address. Members can
|
||||
// choose their own rate-limit key, so where clients also
|
||||
// connect from private addresses this must be set to the
|
||||
// proxy hosts alone.
|
||||
// identified by the connection's own address. Under the
|
||||
// default any client with a private address, directly or
|
||||
// through a proxy, can choose its own rate-limit key, so
|
||||
// where any clients have private addresses this must be set
|
||||
// to the proxy hosts alone.
|
||||
TrustedProxies []netip.Prefix
|
||||
|
||||
// AllowedEgressCIDRs is the set of networks a delivery target
|
||||
|
||||
Reference in New Issue
Block a user