http.trusted_proxies, and a cap on verification mail per account !198

merged merged by cmc on 2026-09-03 18:47 UTC · krz/gitbay:hardening-136 into main

Discussion

cmc

Two of the three items in #136.

Rate limiting behind a proxy. The API limiter keyed anonymous callers by peer address, which is right with nothing in front of the daemon and wrong the day a reverse proxy is added: every caller shares one bucket. http.trusted_proxies lists the proxies' addresses or CIDRs. A request from one of them is attributed to the last X-Forwarded-For hop that is not itself a trusted proxy; from anyone else the header is ignored, so a caller still cannot pick their own bucket. Empty, the default, keeps the peer-only behaviour. A bad entry is refused at config load.

Verification mail. email add enqueued a mail with no limit; an account may now ask for five codes an hour, then gets exit 4 with the count.

Not done: a foreign key on repos.owner_id. The column is polymorphic over users and orgs, so SQLite cannot express the constraint; integrity stays with the delete guards in DeleteUser and DeleteOrg. Left open on #136 for a check in admin stats or the backup verify.

TestClientIPBehindProxy and TestEmailAddThrottled. The Admin wiki page needs a line on trusted_proxies; that lives in krz/gitbay.wiki.

Stacked on !197; no code dependency.

Ref #136

retargeted from readonly-test to main: !197 merged

2026-09-03 18:47 UTC