Description
Audit any IP range usage for admin/gateway endpoints; add tests for boundary CIDRs and spoofing-resistant behavior behind proxies.
Requirements and context
- Document trusted proxy headers configuration.
- Avoid breaking IPv6 deployments.
Suggested execution
- Fork the repo and create a branch:
git checkout -b chore/ip-allowlist-audit
- Work in Callora-Backend (TypeScript / Express).
Primary paths
src/types/ip-range-check.d.ts + call sites (search repo)
- Run
npm run lint, npm run typecheck, and npm test.
Deliverables
- Tests + documentation in PR description.
Test and commit
- Add or extend unit and/or integration tests (
src/**/*.test.ts, tests/integration/**).
- Paste summarized test output in the PR; call out security or data-integrity notes.
Example commit message
chore(security): audit ip allowlist usage
Guidelines
- Tests should cover new behavior and important edge cases.
- Keep changes focused; follow existing patterns in the codebase.
- Timeframe: 96 hours from assignment unless agreed otherwise.
Description
Audit any IP range usage for admin/gateway endpoints; add tests for boundary CIDRs and spoofing-resistant behavior behind proxies.
Requirements and context
Suggested execution
git checkout -b chore/ip-allowlist-auditPrimary paths
src/types/ip-range-check.d.ts+ call sites (search repo)npm run lint,npm run typecheck, andnpm test.Deliverables
Test and commit
src/**/*.test.ts,tests/integration/**).Example commit message
Guidelines