Trust the RFC 1918 ranges as proxies when TRUSTED_PROXIES is unset #333

Open
opened 2026-09-29 09:11:35 +02:00 by clawbot · 1 comment
Collaborator

Directive (top-level sdlc manager, 2026-09-29, verbatim): "270 and the trusted-proxy handling, with RFC 1918 as the default trusted set".

Today TRUSTED_PROXIES defaults to the empty list, so nothing is trusted. Behind the reverse proxy every deployment needs, including upaas, where the proxy reaches the app over a Docker network, every request then keys on the proxy's address and all clients share one bucket per rate limit. Startup warns about it, and the README tells the operator to set the variable.

Definition of done

  • With TRUSTED_PROXIES unset (or empty, which counts as unset), the trusted set is 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. A set value replaces the default entirely. A set value that does not parse still fails startup.

  • The startup warning for an empty list goes, since the list can no longer be empty, along with anything else that exists only for it.

  • The README states the new default and what it means:

    • any peer in those ranges chooses its own rate-limit key through X-Forwarded-For, so an operator whose clients connect directly from private addresses should set the list to the proxy's address alone;
    • clients whose own addresses are private are skipped as trusted hops, and share the proxy's bucket.

    Update the Configuration table, "Trusted proxies" and "Running under upaas", where the proxy on a Docker network is normally covered by the default.

  • Tests cover the default, a set value replacing it, and an invalid value failing startup.

Model: opus-5-5

Directive (top-level sdlc manager, 2026-09-29, verbatim): "270 and the trusted-proxy handling, with RFC 1918 as the default trusted set". Today `TRUSTED_PROXIES` defaults to the empty list, so nothing is trusted. Behind the reverse proxy every deployment needs, including upaas, where the proxy reaches the app over a Docker network, every request then keys on the proxy's address and all clients share one bucket per rate limit. Startup warns about it, and the README tells the operator to set the variable. ## Definition of done - With `TRUSTED_PROXIES` unset (or empty, which counts as unset), the trusted set is `10.0.0.0/8`, `172.16.0.0/12` and `192.168.0.0/16`. A set value replaces the default entirely. A set value that does not parse still fails startup. - The startup warning for an empty list goes, since the list can no longer be empty, along with anything else that exists only for it. - The README states the new default and what it means: - any peer in those ranges chooses its own rate-limit key through `X-Forwarded-For`, so an operator whose clients connect directly from private addresses should set the list to the proxy's address alone; - clients whose own addresses are private are skipped as trusted hops, and share the proxy's bucket. Update the Configuration table, "Trusted proxies" and "Running under upaas", where the proxy on a Docker network is normally covered by the default. - Tests cover the default, a set value replacing it, and an invalid value failing startup. Model: opus-5-5
clawbot self-assigned this 2026-09-29 09:11:35 +02:00
Author
Collaborator

Built in #336 (base next): unset or empty TRUSTED_PROXIES now means the three RFC 1918 ranges, a set value replaces them, the empty-list startup warning is gone, and the README states what the default means and when to narrow it to the proxy alone.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/webhooker/pulls/336 (base `next`): unset or empty `TRUSTED_PROXIES` now means the three RFC 1918 ranges, a set value replaces them, the empty-list startup warning is gone, and the README states what the default means and when to narrow it to the proxy alone. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#333