ashrafee-dev / ashrafee-dev/scamshield-api
Document proxy-aware client IP handling
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 3
- Forks
- 10
- Avg merge
- 14h 44m
- Merged PRs (30d)
- 9
Description
Problem
Rate limiting uses request.client.host directly. Behind a reverse proxy this may rate-limit the proxy itself, while trusting forwarded headers without configuration could allow spoofing.
Acceptance criteria
- Decide and document the supported deployment behavior.
- If proxy headers are supported, configure trusted proxies explicitly.
- Add tests for the selected client-IP behavior.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the rate-limiting code that reads request.client.host and inspect the service's existing deployment or proxy configuration. Decide whether proxy headers are supported and how trusted proxies are configured, then document that behavior and add tests covering the selected client-IP handling. Done means the documented policy, configuration behavior, and tests agree.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- fastapi, python
- Domain
- api, backend, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100