RealIP only reads XFF when the immediate peer sits in TRUSTED_PROXY_CIDRS, so an untrusted client can no longer spoof its source IP while a real client behind a known reverse proxy still resolves correctly. Parses the comma-separated list via a knadh/koanf ProviderWithValue callback (blank or whitespace-only input leaves the built-in default intact), wires the var through both compose files and .env.example, and adds MYSQL_FAKE_* and TURNSTILE_SECRET env aliases. Covered by config_test.go. |
||
|---|---|---|
| .. | ||
| cmd | ||
| internal | ||
| .air.toml | ||
| .gitignore | ||
| .golangci.yml | ||
| config.yaml | ||
| go.mod | ||
| go.sum | ||