diff options
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 5 |
1 files changed, 4 insertions, 1 deletions
@@ -45,6 +45,8 @@ table and deployment notes. and `HttpOnly`, management POSTs need the HMAC `_csrf` token, and the base-domain blog is only editable by the superadmin. - App runs plain HTTP behind a reverse proxy; auth is a JWT cookie. + `HTTPS=true` tells it the proxy has TLS (https links, `Secure` cookie, + HSTS); `TRUST_PROXY=true` that `X-Forwarded-For`'s last entry is the client. - Stdlib `net/http` ServeMux with method+pattern routes. No router library. ## Layout @@ -138,7 +140,8 @@ internal/web/ server.go (host router, middleware, render helpers) minute each), answered with 429 by `s.throttle` and a log line; failed logins are logged with the username and address, and the login body is capped at `maxLoginBody` (64 KB) since it is the one POST outside - `guardPOST`. Flood + `guardPOST`. `s.clientIP` is the peer address, or the last + `X-Forwarded-For` hop with `TRUST_PROXY` (earlier entries are forgeable). Flood control for everything else stays at the reverse proxy (`limit_req`). - **Templates**: each page file is parsed together with its layout (`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all |
