Skip to content

feat: add TRUSTED_PROXIES and trust only local proxies by default - #202

Open
vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:trusted-proxies
Open

vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:trusted-proxies

Conversation

@vlnst

@vlnst vlnst commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

gin trusts all proxies by default, so ClientIP() takes the leftmost X-Forwarded-For entry, which the client controls. Any client can send a fake IP with each request and bypass the rate limiter, both when the app is exposed directly and behind a typical nginx ($proxy_add_x_forwarded_for appends to the client's value).

Now the header is trusted only when the connection comes from a private or loopback address, which covers nginx on the same host or in Docker. TRUSTED_PROXIES (comma-separated IPs/CIDRs) replaces that list, e.g. for a proxy on a public address.

Tested locally: with a spoofed header, requests get 429 after 30/min again, both directly and through a trusted proxy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant