RealIP only reads XFF when the immediate peer sits in TRUSTED_PROXY_CIDRS, so an untrusted client can no longer spoof its source IP while a real client behind a known reverse proxy still resolves correctly. Parses the comma-separated list via a knadh/koanf ProviderWithValue callback (blank or whitespace-only input leaves the built-in default intact), wires the var through both compose files and .env.example, and adds MYSQL_FAKE_* and TURNSTILE_SECRET env aliases. Covered by config_test.go. |
||
|---|---|---|
| .. | ||
| admin | ||
| config | ||
| core | ||
| event | ||
| geoip | ||
| health | ||
| middleware | ||
| notify | ||
| server | ||
| testutil | ||
| token | ||
| turnstile | ||