Skip to main content

resolve_ingress_attribution

Function
This function is defined in the protocols module.
Resolve the real client attribution for an inbound request. Pure and side-effect-free so it is unit-testable in isolation and every seam (rate limiters, connection budget, operator id) consults the same decision.

Signature

Returns

IngressAttribution
class:IngressAttribution. The real client IP is resolved only across hops in trusted_proxies; anything proxy-shaped but unattributable fails closed to the socket peer.Resolution rules:
  • No proxy headers → direct-local (loopback peer) or direct-remote; client_ip is the peer, never fail-closed.
  • Proxy headers present but the socket peer is not a trusted hop → unattributable-proxy, fail_closed=True, client_ip = peer (a spoofable header is never trusted on a directly-reachable gateway).
  • Socket peer is a trusted hop → walk the forwarded chain right→left, peeling trusted hops, and stop at the first untrusted address: that address is the real client. If the chain is empty, fall back to real_ip then the peer. The resolved client must be a literal IP — a malformed/non-IP hop fails closed to the peer. A loopback trusted hop is classified tunnel; otherwise trusted-proxy.

Uses

  • is_loopback
  • IngressAttribution

Source

View on GitHub

praisonaiagents/gateway/protocols.py at line 2680