Satisfy gosec on the proxy count and the request log
CI / chart (pull_request) Successful in 3s
CI / security (pull_request) Successful in 25s
CI / test (pull_request) Successful in 5m42s

G115: the trusted-proxy count is stored as an int64 instead of narrowing
it to int32. G706: the request logger and serverError quote the request
method and route; the logger's remaining taint comes from the wrapped
response writer, so it carries a justified nosec like the other quoted log
lines.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
This commit is contained in:
Niklas Ye
2026-10-09 15:27:45 +02:00
parent eb63e5e138
commit 01922291f6
4 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -132,7 +132,7 @@ func purgeRateLimits(ctx context.Context, db *sql.DB) {
// trustedProxies is how many X-Forwarded-For hops clientAddr trusts. Set once
// by NewRouter from config.
var trustedProxies atomic.Int32
var trustedProxies atomic.Int64
// clientAddr is the address a login is counted against. Behind the gateway
// RemoteAddr is the gateway itself, so the client address is read from