Skip to content

Fix three open bugs - #125

Merged
PascalMinder merged 2 commits into
mainfrom
improvement/documentation
Aug 12, 2026
Merged

PascalMinder merged 2 commits into
mainfrom
improvement/documentation

Conversation

@PascalMinder

Copy link
Copy Markdown
Owner
  • parseAllowedIPAddresses used logger.Fatal on an invalid entry, which
    calls os.Exit and would kill the whole Traefik process on a config
    typo. Additionally it ran before the logger was pointed at stdout, so
    the process died without any message. It now returns an error that New
    propagates, matching how invalid excludedPathPatterns are handled.

  • Reverse-proxy mode panicked with "slice bounds out of range" when a
    request carried neither X-Forwarded-For nor X-Real-IP, because
    requestIPAddresses[:1] had no emptiness guard. Such requests are now
    denied with 403, consistent with the unparsable-IP path.

  • The cache-TTL refresh path only honored ignoreApiFailures, silently
    dropping the ignoreApiTimeout fail-open policy that the cache-miss
    path applied. An IP whose entry had just expired was denied on an API
    timeout the operator had configured to be ignored. Both paths now
    share one handleLookupError helper implementing the full policy.

also fix documentation issues regarding copy and paste issues.

- Fixes copy and paste issues in titles.

- Add missing configuration options to the printConfiguration method.
- parseAllowedIPAddresses used logger.Fatal on an invalid entry, which
  calls os.Exit and would kill the whole Traefik process on a config
  typo. Additionally it ran before the logger was pointed at stdout, so
  the process died without any message. It now returns an error that New
  propagates, matching how invalid excludedPathPatterns are handled.
- Reverse-proxy mode panicked with "slice bounds out of range" when a
  request carried neither X-Forwarded-For nor X-Real-IP, because
  requestIPAddresses[:1] had no emptiness guard. Such requests are now
  denied with 403, consistent with the unparsable-IP path.
- The cache-TTL refresh path only honored ignoreApiFailures, silently
  dropping the ignoreApiTimeout fail-open policy that the cache-miss
  path applied. An IP whose entry had just expired was denied on an API
  timeout the operator had configured to be ignored. Both paths now
  share one handleLookupError helper implementing the full policy.
@PascalMinder PascalMinder self-assigned this Aug 12, 2026
@PascalMinder PascalMinder added documentation Improvements or additions to documentation enhancement New feature or request labels Aug 12, 2026
@PascalMinder
PascalMinder merged commit 6aba284 into main Aug 12, 2026
16 checks passed
@PascalMinder
PascalMinder deleted the improvement/documentation branch August 12, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant