Upgrade to kaya 0.0.3 with trusted-proxy forwarded header support

- bump kaya-core/kaya-rsgi to >= 0.0.3 and add kaya-forwarded: forwarded
  header handling is no longer built into core, it is opt-in via
  ForwardedHeadersMixin and gated on trusted proxy CIDRs
- add TRUSTED_PROXY_CIDRS setting (comma-separated CIDRs, validated at
  startup; empty means no proxy is trusted) and wire the mixin in app.py
- cover trusted/untrusted peers, all-trusted chains and the RFC 7239
  Forwarded header with port in the test suite
- document the new variable in README, .env.example and docker-compose.yml
This commit is contained in:
2026-09-05 08:17:10 +00:00
parent d51f380a3f
commit bba22b357e
9 changed files with 93 additions and 15 deletions
+3 -2
View File
@@ -9,8 +9,9 @@ description = "A clone of https://ifconfig.me/ built on the kaya framework"
readme = "README.md"
requires-python = ">=3.10"
dependencies = [
"kaya-core>=0.0.2",
"kaya-rsgi>=0.0.2",
"kaya-core>=0.0.3",
"kaya-rsgi>=0.0.3",
"kaya-forwarded>=0.0.3",
"granian>=2.0",
"httpx",
"pwo",