ashrafee-dev / ashrafee-dev/scamshield-api

Document proxy-aware client IP handling

Open
#68 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

good first issue
Dominant language
Python
Stars
3
Forks
10
Avg merge
14h 44m
Merged PRs (30d)
9

Description

Problem

Rate limiting uses request.client.host directly. Behind a reverse proxy this may rate-limit the proxy itself, while trusting forwarded headers without configuration could allow spoofing.

Acceptance criteria

  • Decide and document the supported deployment behavior.
  • If proxy headers are supported, configure trusted proxies explicitly.
  • Add tests for the selected client-IP behavior.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the rate-limiting code that reads request.client.host and inspect the service's existing deployment or proxy configuration. Decide whether proxy headers are supported and how trusted proxies are configured, then document that behavior and add tests covering the selected client-IP handling. Done means the documented policy, configuration behavior, and tests agree.

Written by the indexing model from the issue text.

Assessment

Tech stack
fastapi, python
Domain
api, backend, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.