You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 3ff38aa
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/configuration.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,10 +27,10 @@ On Coolify, `DOMAIN` falls back to the domain assigned to the `app` service. See
27
27
28
28
-**Secure cookies.** The session cookie's `Secure` flag follows the public URL from `DOMAIN` / `APP_URL`. The URL is `https://` unless the domain is `localhost` or `127.0.0.1`. Serve the instance over HTTPS so browsers send the cookie.
29
29
-**Client IP.** Rate limits, the audit log and the device list use the client IP, which comes from the proxy's headers:
30
-
1.`X-Real-IP`, if the proxy sets it
31
-
2.otherwise the **right-most**`X-Forwarded-For` entry, which is the hop appended by your proxy. Left-most entries are client-controlled and ignored.
30
+
1.the **right-most**`X-Forwarded-For` entry, which is the hop appended by your proxy. Left-most entries are client-controlled and ignored.
31
+
2.`X-Real-IP`, only when there is no `X-Forwarded-For` header at all.
32
32
33
-
This assumes a **single trusted reverse proxy** directly in front of Dispatch (Traefik on Coolify, the bundled Caddy, or your nginx). With a second proxy or CDN in front, e.g. Cloudflare → Traefik, configure the inner proxy to set`X-Real-IP` to the real client address. Otherwise all requests appear to come from the CDN. Never publish port 3000 to the internet without a proxy, because clients could then send these headers themselves.
33
+
This assumes a **single trusted reverse proxy** directly in front of Dispatch (Traefik on Coolify, the bundled Caddy, or your nginx); all of them append the connecting address to `X-Forwarded-For` by default. With a CDN in front (e.g. Cloudflare → Traefik), the right-most hop is the CDN's edge address, so per-IP rate limits apply per edge location; configure your inner proxy to *replace*`X-Forwarded-For` with the real client address (e.g. Cloudflare's `CF-Connecting-IP`) if you need exact client IPs. Never publish port 3000 to the internet without a proxy, because clients could then send these headers themselves.
0 commit comments