Skip to content

0.4.1 — client IP behind Cloudflare

Choose a tag to compare

@Vitrus-Dev Vitrus-Dev released this 24 Sep 11:58
· 8 commits to main since this release

Fix: one visit counted as several visitors behind Cloudflare

The client IP now comes from cf-connecting-ip when it is present, and only then from the first value of x-forwarded-for.

Behind Cloudflare and a reverse proxy that rewrites x-forwarded-for (Caddy does this by default for clients it does not trust), the first value of that header is the Cloudflare edge that connected, not the visitor, and it changes from request to request. Because the anonymous visitor id is a daily-salted hash of IP and user-agent, a single page visit — its pageview, an outbound click, and the Web Vitals beacon — could be hashed into several visitors, each with its own zero-length session.

Symptoms you may have seen: sessions roughly doubled, pages-per-session under 1, a bounce rate near 100%, and funnel steps after the first page empty.

What this does not fix: events already stored. Visitor ids are one-way hashes, so past sessions cannot be re-joined. Numbers are correct from the moment you upgrade.

If you run behind Cloudflare without Caddy, or with trusted_proxies configured, you were not affected.