Explorar o código

Pass the Cloudflare visitor address to the production container (#359)

* Trust Cloudflare's visitor address in production

Production has been proxied by Cloudflare since August, but the container
never received TRUST_CF_CONNECTING_IP, so the rate limiter counted every
visitor as the edge address it arrived through.

* Trust Cloudflare's visitor address on staging too
Bernt Christian Egeland hai 3 semanas
pai
achega
b4f4b051ed
Modificáronse 1 ficheiros con 4 adicións e 0 borrados
  1. 4 0
      .github/workflows/deploy-prod.yml

+ 4 - 0
.github/workflows/deploy-prod.yml

@@ -85,6 +85,10 @@ jobs:
                 BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET}
                 BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET}
                 NEXT_PUBLIC_APP_URL: ${APP_URL}
                 NEXT_PUBLIC_APP_URL: ${APP_URL}
                 TORQVOICE_MODE: cloud
                 TORQVOICE_MODE: cloud
+                # Production sits behind Cloudflare and the origin only accepts its
+                # edges, so the visitor address is the one Cloudflare says it is.
+                # Without this every visitor shares the edge's rate-limit bucket.
+                TRUST_CF_CONNECTING_IP: "true"
                 STRIPE_SECRET_KEY: ${STRIPE_SECRET_KEY}
                 STRIPE_SECRET_KEY: ${STRIPE_SECRET_KEY}
                 STRIPE_WEBHOOK_SECRET: ${STRIPE_WEBHOOK_SECRET}
                 STRIPE_WEBHOOK_SECRET: ${STRIPE_WEBHOOK_SECRET}
                 STRIPE_PRO_PRICE_ID: ${STRIPE_PRO_PRICE_ID}
                 STRIPE_PRO_PRICE_ID: ${STRIPE_PRO_PRICE_ID}