caddy/modules
Matthew Holt deedf8abb0
caddyhttp: Optionally use forwarded IP for remote_ip matcher
The remote_ip matcher was reading the X-Forwarded-For header by default, but this behavior was not documented in anything that was released. This is also a less secure default, as it is trivially easy to spoof request headers. Reading IPs from that header should be optional, and it should not be the default.

This is technically a breaking change, but anyone relying on the undocumented behavior was just doing so by coincidence/luck up to this point since it was never in any released documentation. We'll still add a mention in the release notes about this.
2020-12-10 16:09:30 -07:00
..
caddyhttp caddyhttp: Optionally use forwarded IP for remote_ip matcher 2020-12-10 16:09:30 -07:00
caddypki acme_server: fix reload of acme database (#3874) 2020-11-23 13:58:26 -07:00
caddytls go.mod: Upgrade some dependencies 2020-12-08 14:06:52 -07:00
filestorage httpcaddyfile: Minor fixes to parsing storage options 2020-05-01 09:34:32 -06:00
logging logging: Fix for IP filtering 2020-11-02 16:01:58 -07:00
metrics metrics: fix handler to not run the next route (#3769) 2020-10-01 10:57:14 -06:00
standard metrics: Initial integration of Prometheus metrics (#3709) 2020-09-17 12:01:20 -06:00