Trust the RFC 1918 ranges as proxies when TRUSTED_PROXIES is unset (closes #333) #336

Open
clawbot wants to merge 3 commits from issue-333-trust-rfc1918-proxies into next
3 Commits
Author SHA1 Message Date
clawbot 3050c2e3b5 Point to the proxy's access log for a login flood's source
check / check (push) Successful in 4m49s
No log line records the client address taken from X-Forwarded-For,
so the login endpoint section no longer says the source shows in the
failure logs; it names the proxy's access log instead.

Model: opus-5-5
2026-09-29 09:01:49 +00:00
clawbot dcb26a239f Say that any private-addressed client can choose its rate-limit key
Under the default, a client with a private address picks its own
rate-limit key through X-Forwarded-For whether it connects directly or
through the proxy, so the README and the TrustedProxies comment now
tell an operator with any such clients to set the list to the proxy
alone. The login endpoint section no longer assumes the proxy is
uncovered by default.

Model: opus-5-5
2026-09-29 08:58:10 +00:00
clawbot b12e204d1f Trust the RFC 1918 ranges as proxies when TRUSTED_PROXIES is unset (closes #333)
Unset or empty, TRUSTED_PROXIES now defaults to 10.0.0.0/8,
172.16.0.0/12 and 192.168.0.0/16, so a reverse proxy reaching the app
over a Docker network or a private LAN gets per-client rate-limit
buckets without configuration. A set value replaces the default; an
unparseable one still fails startup.

The startup warning for an empty list goes, with its test hook and
test, since the default is no longer empty. The README's
configuration table, Trusted proxies, upaas and reverse-proxy sections
describe the new default and when to narrow it to the proxy alone.

Model: opus-5-5
2026-09-29 08:58:10 +00:00