v0.140.0 is a small release — one file, 37 lines added — but one of the two changes is the kind of thing that bites you only when it matters, so it's worth a few words.
What changed
-
serve_on, and trust X-Forwarded-For only from the proxy (#671) — the machweb framework now scopes trust of the
X-Forwarded-Forheader to requests that arrive through the configured proxy.serve_onis the new entry point that wires this up. - map_free: reclaim a transient map on the main goroutine's arena (#667 / #669) — a transient map allocated on the main goroutine's arena is now explicitly freed instead of lingering until the arena is torn down.
- v0.140.0 — the version bump that carries the above.
Why it matters
The X-Forwarded-For change is the interesting one. The header exists so a reverse proxy can tell your app the real client IP when it terminates the connection. The problem is that the header is just text — any client can send it. If your app trusts X-Forwarded-For unconditionally, a request that never went through your proxy can still claim to be from any IP it likes. That defeats IP-based rate limiting, geo checks, allow/deny lists, and audit logs.
The fix is to trust the header only on requests you know came from your proxy — typically by checking the peer address against the proxy's address. That's what this change does. It's a small, unglamorous guard, but it's the difference between "the proxy tells me the client IP" and "anyone tells me the client IP."
The map_free change is a memory hygiene fix in the same vein: an arena allocator is a great fit for a request's lifetime, but a transient map that outlives its usefulness still holds a slot until the arena resets. Reclaiming it explicitly keeps peak memory from ratcheting up on long-lived arenas.
Neither change is flashy. Both are the kind of thing you only notice when you're debugging a spoofed-IP incident or a slow memory climb — at which point you wish you'd done them earlier.
Top comments (0)