etherpad-lite/src
webzwo0i ceb09ce99a
security: Support proxy with rate limiting and include CI test coverage for nginx rev proxy (#4373)
Previously Etherpad would not pass the correct client IP address through and this caused the rate limiter to limit users behind reverse proxies.  This change allows Etherpad to use a client IP passed from a reverse proxy.

Note to devs: This header can be spoofed and spoofing the header could be used in an attack.  To mitigate additional *steps should be taken by Etherpad site admins IE doing rate limiting at proxy.*  This only really applies to large scale deployments but it's worth noting.
2020-10-01 10:39:01 +01:00
..
locales i18n: Localize /admin pages (#4380) 2020-10-01 10:15:27 +01:00
node security: Support proxy with rate limiting and include CI test coverage for nginx rev proxy (#4373) 2020-10-01 10:39:01 +01:00
static webaccess: Move pre-authn authz check to a separate hook 2020-09-27 21:19:58 +01:00
templates i18n: Localize /admin pages (#4380) 2020-10-01 10:15:27 +01:00
ep.json Refactor startup/shutdown for tests 2020-09-22 11:07:21 +01:00
etherpad_icon.svg Change favicon to be closer to new style 2020-04-19 18:20:21 +02:00
package-lock.json security: Support proxy with rate limiting and include CI test coverage for nginx rev proxy (#4373) 2020-10-01 10:39:01 +01:00
package.json security: Support proxy with rate limiting and include CI test coverage for nginx rev proxy (#4373) 2020-10-01 10:39:01 +01:00
README.md remove one less warning during install by having a readme placeholder 2013-02-10 03:04:08 +00:00
web.config Add IIS config file 2012-10-25 10:22:28 -07:00

Ignore this file and see the file in the base installation folder