Area: security middleware
Problem: Accepting forwarded headers blindly can be abused outside trusted proxy setup.
Testing gap: No environment-aware tests enforcing trusted proxy behavior.
Acceptance tests: Tests verifying header trust disabled unless proxy config enables it.
Area: security middleware
Problem: Accepting forwarded headers blindly can be abused outside trusted proxy setup.
Testing gap: No environment-aware tests enforcing trusted proxy behavior.
Acceptance tests: Tests verifying header trust disabled unless proxy config enables it.