- limiter_key: an empty client_ip(req) under trust_proxy no longer keys on the literal "ip:" -- falls through to net.peer(req.conn) instead, same as the untrusted-default path - the bug: every client omitting X-Forwarded-For shared ONE bucket, so one could exhaust it and deny/hide the rest - curl availability check added alongside the existing woc/wovm check (the limiter gate legs drive the server with it) - new gate leg: LIMIT+1 sequential no-XFF requests must all be 200 (own key per connection, via a fresh ephemeral port each time) -- confirmed it fails against the pre-fix code (6th comes back 429) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> (cherry picked from commit 831e9d8e6b1ef39cd938783dbc47c1abe6d53211) |
||
|---|---|---|
| .. | ||
| idempotent.wo | ||
| keypool.wo | ||
| limiter.wo | ||
| store.wo | ||