[ENG-4060] Accept a peer address from Fetch runtimes - #302
Merged
Merged
Conversation
Add a peerAddress option: the host supplies the transport peer it knows (for example from Deno's handler info or Bun's server), and that address counts as the peer for client address resolution, including trustedProxy. fetchGuard() and the Supabase tunnel pass the host's handler arguments on. With trustedProxy set and no usable peer, the guard warns once. A response screened for a request reuses the address resolved for that request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Well-structured feature adding host-supplied peer addresses across runtimes. 🎯 Quality: 100% Elite · 📦 Size: Medium 🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the 📈 This month: Your 161st PR — above team average · Averaging Excellent |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
screenResponse(response, request) now asks peerAddress when the guard did not screen that request first, passing any further arguments on as the host's handler arguments. A request the guard already screened keeps its request-phase address. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
/review |
mariojgt
approved these changes
Sep 29, 2026
daniloradovic
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A WHATWG
Requestcarries no transport peer. On Fetch runtimes the client address therefore always read asunavailable, and atrustedProxypolicy could never apply.New option:
peerAddress. The host supplies the peer it knows, for example(req, info) => info.remoteAddr.hostnameon Deno or(req, server) => server.requestIP(req)?.addresson Bun.fetch(handler)already receives those arguments.fetchGuard()(request, ...args)and the Supabase tunnel now pass them on.trustedProxy.onErrorand supplies no peer. A value that is not an address supplies no peer.Warning. With
trustedProxyset and no usable peer, the guard warns once, throughonErroror on the console.Response screening for a request the guard has already screened reuses that request's resolved address. For a request it has not screened,
screenResponse(response, request, ...args)resolves the address the same way, throughpeerAddress, passing any further arguments on as the host's handler arguments.Without the new option, behaviour is unchanged.
AGENT-INSTALL.mdand the declarations describe it. BecauseAGENT-INSTALL.mdchanged, the hostile field-test run is still outstanding. It has to run immediately after the release that contains this change: a run before that release inspects the previously published docs.Validation: full suite, typecheck, build, and the capability check.
Part of ENG-4060.
🤖 Generated with Claude Code