Technical notes on web development, DevOps, and AI integration.
1 article
The first X-Forwarded-For entry is attacker-controlled. Which address behind Cloudflare and nginx actually deserves a rate limiter's trust.
TL;DR: A burst of password guesses on an admin login exposed a flaw: the rate limiter trusted an attacker-controlled X-Forwarded-For entry. The fix prefers Cloudflare's CF-Connecting-IP header, then the last proxy entry, then X-Real-IP, and finally the raw connection address. Per-account keys pairing IP with email, 429 responses with Retry-After, and bounded memory keep the limiter effective.