Skip to content

Fix/limit forwarded ip count - #126

Open
PascalMinder wants to merge 3 commits into
mainfrom
fix/limit-forwarded-ip-count
Open

PascalMinder wants to merge 3 commits into
mainfrom
fix/limit-forwarded-ip-count

Conversation

@PascalMinder

@PascalMinder PascalMinder commented Aug 12, 2026 •

Copy link
Copy Markdown
Owner

Contains enhancements for the usage of the geolocation API.

  • Limit the number of forwarded IPs evaluated per request
  • Negatively cache failed country lookups
  • Harden the geolocation API client plumbing

Theoretically an attacker could forge the X-Forwared-For or X-Real-IP
header content with a long number of IP addresses. This would lead to a
sequential look-up via the API. Each request can so take up to
len(chain) * apiTimeoutMs time to resolve.

Requests with more than 10 IPs across both headers are now denied with
the same log-and-403 handling as unparsable addresses.
A failed lookup cached nothing, so every subsequent request from that
IP re-attempted the API and waited out up to apiTimeoutMs again. Failed
lookups are now also cached as ipEntries for a short time (30s).
Depending on the configuration they are allowed or denied.

ipEntry gained a String method so cache log lines stay readable and
distinguish negative entries.
- Use on shared client per middleware, and the requests use
  NewRequestWithContext with the incoming request's context.
- Fix issue with non-200 early return requests. Defer Body.Close().
- Bound request body read to a fixed size.
- The shared transport raises MaxIdleConnsPerHost from the default 2
  to 16.
@PascalMinder PascalMinder self-assigned this Aug 12, 2026
@PascalMinder PascalMinder added the enhancement New feature or request label Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant