- Backend retries DB connection at startup (up to 180s) so host reboots no longer crash-loop it; add backend and frontend healthchecks - Docker log rotation (json-file 10m x 3) on all services - ntfy alerts use X-Real-IP (set by nginx after real_ip resolution) instead of the client-controlled first X-Forwarded-For entry - Frontend build on Node 24 LTS with package-lock.json + npm ci; axios 1.20.0, vite 5.4.21 - README: backup/restore/rollback runbook, real-IP proxy trust notes - Release-Notes/v1.1.md; version 1.1.0 Co-Authored-By: Claude Opus 5.5 <[email protected]>
11 lines
405 B
Python
11 lines
405 B
Python
from fastapi import Request
|
|
|
|
|
|
def client_ip(request: Request) -> str:
|
|
"""Real client IP as resolved by the frontend nginx (real_ip module).
|
|
|
|
X-Forwarded-For is client-controlled and must not be trusted here; nginx
|
|
sets X-Real-IP from $remote_addr after walking past trusted proxies.
|
|
"""
|
|
return request.headers.get("X-Real-IP") or (request.client.host if request.client else "unknown")
|