- bump kaya-core/kaya-rsgi to >= 0.0.3 and add kaya-forwarded: forwarded
header handling is no longer built into core, it is opt-in via
ForwardedHeadersMixin and gated on trusted proxy CIDRs
- add TRUSTED_PROXY_CIDRS setting (comma-separated CIDRs, validated at
startup; empty means no proxy is trusted) and wire the mixin in app.py
- cover trusted/untrusted peers, all-trusted chains and the RFC 7239
Forwarded header with port in the test suite
- document the new variable in README, .env.example and docker-compose.yml