Forráskód Böngészése

Pass the Cloudflare visitor address to the production container (#359)

* Trust Cloudflare's visitor address in production

Production has been proxied by Cloudflare since August, but the container
never received TRUST_CF_CONNECTING_IP, so the rate limiter counted every
visitor as the edge address it arrived through.

* Trust Cloudflare's visitor address on staging too
Bernt Christian Egeland 3 hete
szülő
commit
b4f4b051ed
1 módosított fájl, 4 hozzáadás és 0 törlés
  1. 4 0
      .github/workflows/deploy-prod.yml

+ 4 - 0
.github/workflows/deploy-prod.yml

@@ -85,6 +85,10 @@ jobs:
                 BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET}
                 NEXT_PUBLIC_APP_URL: ${APP_URL}
                 TORQVOICE_MODE: cloud
+                # Production sits behind Cloudflare and the origin only accepts its
+                # edges, so the visitor address is the one Cloudflare says it is.
+                # Without this every visitor shares the edge's rate-limit bucket.
+                TRUST_CF_CONNECTING_IP: "true"
                 STRIPE_SECRET_KEY: ${STRIPE_SECRET_KEY}
                 STRIPE_WEBHOOK_SECRET: ${STRIPE_WEBHOOK_SECRET}
                 STRIPE_PRO_PRICE_ID: ${STRIPE_PRO_PRICE_ID}