You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5533a78
Browse filesBrowse the repository at this point in the historyBrowse files
Reject requests whose client IP doesn't match the JWT remoteAddress
Abusers were sharing a single session across many IPs (download mirrors,
scraper farms), evading the per-(session, path) limiter by spreading
requests across distinct paths while driving seeder load.
The JWT already carries remoteAddress from issuance — compare it to the
request's X-Forwarded-For IP with a /24 (v4) or /64 (v6) mask to tolerate
ISP-local and mobile-carrier churn. Fails open on unparseable claims and
is gated behind ENFORCE_SESSION_IP for quick disable.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Usage: "reject requests whose client IP doesn't match the remoteAddress claim in the JWT (normalized to /24 for v4, /64 for v6). Disable to unblock mobile users if false positives appear.",
134
+
EnvVar: "ENFORCE_SESSION_IP",
135
+
},
128
136
)
129
137
}
130
138
139
+
// sameSubnet reports whether two IP strings share the same subnet prefix
140
+
// (/24 for IPv4, /64 for IPv6). Returns true when either side is unparseable
141
+
// so we fail open rather than 429 a legitimate user on a malformed claim.
0 commit comments