v1.7.0 — Trusted-proxy IP resolution
Fixed
- Client IP resolution no longer trusts forwarding headers from anyone. The connecting address is the customer unless it belongs to a proxy the plugin trusts: Cloudflare (published ranges fetched daily, bundled fallback), a proxy on the same host (private or carrier-grade NAT peer, detected automatically, so managed hosts need no configuration), or a proxy you declare. A bot can no longer forge its address to evade the IP blacklist and bans or get innocent addresses banned.
Added
- Lists > Trusted Proxies: declared proxy ranges (IPv4 and IPv6), a diagnostic showing how the current request was resolved, Cloudflare range status with a Refresh link, and a clearly marked legacy switch restoring the old behavior.
- Detection of an undeclared public-address proxy with one-click trust or dismiss. While undeclared, the automatic IP-keyed rules pause so every customer is not treated as one address; blacklists, allowlist, and all non-IP rules keep working.
- IPv6 support in every IP list and CIDR match.
Full details in CHANGELOG.md.