-
Notifications
You must be signed in to change notification settings - Fork 0
Harden the Cloudflare edge, trusted proxy chain, and abuse limits #253
Copy link
Copy link
Open
Labels
backendBackend servicesBackend servicesinfraInfrastructure and toolingInfrastructure and toolingpost-launchAfter Public Launch #86–#104; see post-launch-ui-backlog.mdAfter Public Launch #86–#104; see post-launch-ui-backlog.mdready-for-agentReady for agent implementationReady for agent implementationrealtimeRealtime messaging and voiceRealtime messaging and voicesecuritySecurity and permissionsSecurity and permissionsstoryVertical-slice storyVertical-slice story
Description
Activity
Metadata
Metadata
Assignees
Labels
backendBackend servicesBackend servicesinfraInfrastructure and toolingInfrastructure and toolingpost-launchAfter Public Launch #86–#104; see post-launch-ui-backlog.mdAfter Public Launch #86–#104; see post-launch-ui-backlog.mdready-for-agentReady for agent implementationReady for agent implementationrealtimeRealtime messaging and voiceRealtime messaging and voicesecuritySecurity and permissionsSecurity and permissionsstoryVertical-slice storyVertical-slice story
Parent
#107 (identified by #238)
What to build
Harden Chanter's public edge and abuse controls. Client identity must come only from trusted proxies, expensive or sensitive endpoints must have distributed limits, browser defenses must be explicit, and the origin must not be reachable by bypassing Cloudflare controls.
Acceptance criteria
X-Forwarded-*or identity headers.Blocked by