The remote_ip plug previously trusted Cf-Connecting-Ip and X-Forwarded-For on every request, so any client reaching a pod directly (cluster-internal, kubectl port-forward, misconfigured Service) could spoof conn.remote_ip, which flows into session storage and logs. Now only honour those headers when the immediate TCP peer sits inside a configured CIDR list. Default list covers loopback, RFC1918, CGNAT, link-local, and IPv6 ULA — matches the k8s pod/service network. Override via config :microwaveprop, :trusted_proxies, or per-environment via the TRUSTED_PROXY_CIDRS env var in runtime.exs. Also refresh the stale "nginx/dokku proxy" moduledoc — deployment has been k8s + Cloudflare for a while. |
||
|---|---|---|
| .. | ||
| components | ||
| controllers | ||
| live | ||
| plugs | ||
| endpoint.ex | ||
| gettext.ex | ||
| live_table_footer.ex | ||
| live_table_resource.ex | ||
| metrics_plug.ex | ||
| router.ex | ||
| skew_t.ex | ||
| telemetry.ex | ||
| user_auth.ex | ||