From f9f77d0099724ae7cf59f069af7845c8c8e1c3a4 Mon Sep 17 00:00:00 2001 From: vlnst Date: Wed, 7 Oct 2026 04:25:18 +0300 Subject: [PATCH] feat: add TRUSTED_PROXIES and trust only local proxies by default --- docker-compose.example.yml | 1 + main.go | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/docker-compose.example.yml b/docker-compose.example.yml index 11f0e83..7ff2184 100644 --- a/docker-compose.example.yml +++ b/docker-compose.example.yml @@ -9,6 +9,7 @@ services: - JWT_SIGNING_SECRET=secret - SCRAPER=api # - API_KEY=... + # - TRUSTED_PROXIES=203.0.113.10 ports: - '80:8080' restart: 'always' diff --git a/main.go b/main.go index 2752b66..bd3a63d 100644 --- a/main.go +++ b/main.go @@ -10,6 +10,7 @@ import ( "io/fs" "net/http" "os" + "strings" "github.com/gin-gonic/gin" healthcheck "github.com/tavsec/gin-healthcheck" @@ -44,6 +45,16 @@ func main() { r := gin.Default() + // gin trusts X-Forwarded-For from any client by default, which lets clients + // pick their own IP and bypass the rate limiter. + trustedProxies := []string{"127.0.0.0/8", "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "::1/128", "fc00::/7"} + if v := os.Getenv("TRUSTED_PROXIES"); v != "" { + trustedProxies = strings.Split(v, ",") + } + if err := r.SetTrustedProxies(trustedProxies); err != nil { + panic(err) + } + templ := template.Must(template.New("").ParseFS(templates, "templates/*")) r.SetHTMLTemplate(templ)