Document proxy-aware client IP handling

Open
#68 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
55/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
fastapi, python
Domain
api, backend, security

Research direction

Locate the rate-limiting code that reads request.client.host and inspect the service's existing deployment or proxy configuration. Decide whether proxy headers are supported and how trusted proxies are configured, then document that behavior and add tests covering the selected client-IP handling. Done means the documented policy, configuration behavior, and tests agree.

Written by the indexing model from the issue text.

Description

good first issue

Problem

Rate limiting uses request.client.host directly. Behind a reverse proxy this may rate-limit the proxy itself, while trusting forwarded headers without configuration could allow spoofing.

Acceptance criteria

  • Decide and document the supported deployment behavior.
  • If proxy headers are supported, configure trusted proxies explicitly.
  • Add tests for the selected client-IP behavior.
Dominant language
Python
Stars
3
Forks
10
Avg merge
14h 44m
Merged PRs (30d)
9

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from ashrafee-dev/scamshield-api

All issues in ashrafee-dev/scamshield-api

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.