- Updated IP geolocation to check CF-Connecting-IP header first
- Added support for X-Real-IP header as additional fallback
- Updated rate limiter to use same header priority for consistency
- Headers checked in order: CF-Connecting-IP > X-Forwarded-For > X-Real-IP > remote_ip
This ensures proper client IP detection when the site is behind Cloudflare.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Added custom content-security-policy to put_secure_browser_headers
- Allowed script sources:
- https://js.sentry-cdn.com for Sentry SDK
- https://cdnjs.cloudflare.com for OverlappingMarkerSpiderfier
- Allowed connect sources for Sentry error reporting:
- https://*.ingest.sentry.io
- https://*.sentry.io
- Removed custom ContentSecurityPolicy plug in favor of built-in configuration
This properly configures the Content Security Policy to allow all necessary
external resources while maintaining security.
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>