R-776: kimai sees each visitor behind the tunnel (trusted docker networks; 9202 checklist 3.6 re-measure owed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:17:31 +02:00
parent d955df1f15
commit 462e66f0ca
+5
View File
@@ -22,6 +22,11 @@ services:
- DATABASE_URL=mysql://kimai:${DB_PASSWORD}@kimai-db:3306/kimai?charset=utf8mb4&serverVersion=11.6.2-MariaDB
- ADMINMAIL=${ADMIN_EMAIL:-admin@example.com}
- ADMINPASS=${ADMIN_PASSWORD}
# R-776 (R-753, controller >= 0.286.0): trust the docker networks as proxies (the image default is
# nginx,localhost,127.0.0.1, so traefik was not trusted and every login/reset limiter keyed on traefik's one address
# — a stranger's tries throttled the household too). Symfony then walks X-Forwarded-For from the RIGHT: the tunnel's
# real visitor, or the LAN client. The bookstack shape (APP_PROXIES); 9202 re-measure owed (checklist 3.6).
- TRUSTED_PROXIES=127.0.0.1,172.16.0.0/12
volumes:
- kimai_var:/opt/kimai/var
networks: