Skip to content

v1.7.0 — Trusted-proxy IP resolution

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 02 Sep 20:48
· 24 commits to main since this release

Fixed

  • Client IP resolution no longer trusts forwarding headers from anyone. The connecting address is the customer unless it belongs to a proxy the plugin trusts: Cloudflare (published ranges fetched daily, bundled fallback), a proxy on the same host (private or carrier-grade NAT peer, detected automatically, so managed hosts need no configuration), or a proxy you declare. A bot can no longer forge its address to evade the IP blacklist and bans or get innocent addresses banned.

Added

  • Lists > Trusted Proxies: declared proxy ranges (IPv4 and IPv6), a diagnostic showing how the current request was resolved, Cloudflare range status with a Refresh link, and a clearly marked legacy switch restoring the old behavior.
  • Detection of an undeclared public-address proxy with one-click trust or dismiss. While undeclared, the automatic IP-keyed rules pause so every customer is not treated as one address; blacklists, allowlist, and all non-IP rules keep working.
  • IPv6 support in every IP list and CIDR match.

Full details in CHANGELOG.md.