Upgrade to kaya 0.0.3 with trusted-proxy forwarded header support
CI / Build and push docker image (push) Successful in 1m25s

- bump kaya-core/kaya-rsgi to >= 0.0.3 and add kaya-forwarded: forwarded
  header handling is no longer built into core, it is opt-in via
  ForwardedHeadersMixin and gated on trusted proxy CIDRs
- add TRUSTED_PROXY_CIDRS setting (comma-separated CIDRs, validated at
  startup; empty means no proxy is trusted) and wire the mixin in app.py
- cover trusted/untrusted peers, all-trusted chains and the RFC 7239
  Forwarded header with port in the test suite
- document the new variable in README, .env.example and docker-compose.yml
This commit is contained in:
2026-09-05 16:18:37 +08:00
committed by woggioni
parent d51f380a3f
commit 47d2280970
9 changed files with 93 additions and 15 deletions
+5 -2
View File
@@ -29,11 +29,14 @@ idna==3.19
# via
# anyio
# httpx
kaya-core==0.0.2
kaya-core==0.0.3
# via
# kaya-forwarded
# kaya-rsgi
# pyfconfig (pyproject.toml)
kaya-rsgi==0.0.2
kaya-forwarded==0.0.3
# via pyfconfig (pyproject.toml)
kaya-rsgi==0.0.3
# via pyfconfig (pyproject.toml)
pwo==0.1.2
# via