resolve_ingress_attribution
Function
This function is defined in the protocols module.Resolve the real client attribution for an inbound request. Pure and side-effect-free so it is unit-testable in isolation and every seam (rate limiters, connection budget, operator id) consults the same decision.
Signature
Returns
IngressAttribution
class:
IngressAttribution. The real client IP is resolved only
across hops in trusted_proxies; anything proxy-shaped but
unattributable fails closed to the socket peer.Resolution rules:- No proxy headers →
direct-local(loopback peer) ordirect-remote;client_ipis the peer, never fail-closed. - Proxy headers present but the socket peer is not a trusted hop →
unattributable-proxy,fail_closed=True,client_ip= peer (a spoofable header is never trusted on a directly-reachable gateway). - Socket peer is a trusted hop → walk the forwarded chain right→left,
peeling trusted hops, and stop at the first untrusted address: that
address is the real client. If the chain is empty, fall back to
real_ipthen the peer. The resolved client must be a literal IP — a malformed/non-IP hop fails closed to the peer. A loopback trusted hop is classifiedtunnel; otherwisetrusted-proxy.
Uses
is_loopbackIngressAttribution
Source
View on GitHub
praisonaiagents/gateway/protocols.py at line 2680
