writeonce/docs
shoney.arickathil 37a63192c6 fix(porch-store): trust_proxy falls back to net.peer on an absent XFF
- limiter_key: an empty client_ip(req) under trust_proxy no longer keys
  on the literal "ip:" -- falls through to net.peer(req.conn) instead,
  same as the untrusted-default path
- the bug: every client omitting X-Forwarded-For shared ONE bucket,
  so one could exhaust it and deny/hide the rest
- curl availability check added alongside the existing woc/wovm check
  (the limiter gate legs drive the server with it)
- new gate leg: LIMIT+1 sequential no-XFF requests must all be 200
  (own key per connection, via a fresh ephemeral port each time) --
  confirmed it fails against the pre-fix code (6th comes back 429)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 831e9d8e6b1ef39cd938783dbc47c1abe6d53211)
2026-09-15 01:15:30 +02:00
..
examples fix(porch-store): trust_proxy falls back to net.peer on an absent XFF 2026-09-15 01:15:30 +02:00
guides docs(db2-migrate): close out iteration 12 2026-08-31 21:54:27 +02:00
plan docs(lang42): story, spec and plan for bounded subprocess 2026-09-01 22:19:25 +02:00
stories feat(query-corpus): iteration 9g corpus #1 — skillhost needs no new query grammar 2026-09-15 01:15:30 +02:00
superpowers docs(porch-store): call replies are scalars — response goes via the table 2026-09-15 01:15:30 +02:00
00-code-review.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-databasev2-chain-review.md fix(db2-keys): delete on a keys-resident table was memory corruption 2026-08-30 20:37:27 +02:00
00-dependency-graph.md docs(lang42): close out iteration 42 2026-09-01 22:19:25 +02:00
00-doc-audit.md refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00
00-git-commit-history.md docs(commit-history): register porch-store Phase C 2026-09-15 01:15:30 +02:00
00-link-audit.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-principles.md docs: amend principle 7 — the log is authoritative, residency is declared 2026-08-26 22:42:27 +02:00
01-problem.md docs: remove stale old-runtime docs; abandon the ##ui frontend track 2026-08-17 20:06:36 +02:00
08-project-structure.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
2026-08-27-chat-drain-finding.md fix(chat gate): every leg starts its own server — and it found a real bug 2026-08-27 23:27:46 +02:00