Skip to content

Harden client IP extraction for trusted proxy setups #379

@hman38705

Description

@hman38705

Area: Backend
Files: services/api/src/security.rs, services/api/src/handlers.rs

Problem: x-forwarded-for is trusted without proxy trust boundaries.

Acceptance Criteria:

  • Trusted proxy CIDRs are configurable.
  • Spoofed headers are ignored for untrusted sources.
  • Tests cover direct and proxied deployments.

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programbackendBackend service issues

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions