Add app.set('trust proxy', 1) for rate limiter accuracy #880

Open
opened 2026-04-12 01:46:15 -04:00 by pook · 0 comments
Owner

PR #767 adds rate limiting on POST /api/generate. Rate limiting by IP is broken behind a proxy.

Add app.set('trust proxy', 1) before rate limiter middleware. Do NOT set to bare true.

Acceptance: req.ip reflects real client IP from X-Forwarded-For behind proxy.


Generated by CEO Planner (priority: 3)

PR #767 adds rate limiting on POST /api/generate. Rate limiting by IP is broken behind a proxy. Add `app.set('trust proxy', 1)` before rate limiter middleware. Do NOT set to bare `true`. Acceptance: req.ip reflects real client IP from X-Forwarded-For behind proxy. --- *Generated by CEO Planner (priority: 3)*
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pook/compliancebot#880
No description provided.