Skip to content

feat(session): expose the proxy-aware client IP used for IP binding - #97

Merged
allen0099 merged 1 commit into
masterfrom
feat/public-client-ip
Sep 25, 2026
Merged

allen0099 merged 1 commit into
masterfrom
feat/public-client-ip

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #87.

Problem

With ip_binding on, the middleware checks each request against the address from the private _get_client_ip(). Behind one of trusted_proxies, that address comes from X-Forwarded-For / X-Real-IP. Applications passed request.client.host to create_session(), but behind the proxy that is the proxy's address. The bound IP never matched, so every session was rejected on its second request.

Changes

  • get_client_ip(connection, config) is now public in session/middleware.py and exported from fastapi_cachex.session. Its logic is unchanged, and the middleware's _get_client_ip method is kept.
  • get_session_client_ip is a new dependency, exported from fastapi_cachex.session, with the ClientIPDep alias in session.dependencies next to the other *Dep aliases. It resolves the address using the registered SessionManager's config.
  • docs/SESSION.md: the login example uses ClientIPDep. The reverse-proxy section now shows both options instead of only warning.
  • CHANGELOG [Unreleased] Added entry.

Tests

tests/session/test_client_ip.py:

  • get_client_ip behind a trusted and an untrusted peer, and with no peer.
  • An end-to-end test with TestClient as the trusted proxy: a session bound via ClientIPDep is honoured on the next request.
  • A control showing that binding request.client.host there is rejected.

The existing test_starlette_middleware.py tests now import the public name.

Local: ruff check/format and mypy (package strict, tests, scripts) are clean. zensical build --strict passes. Against live Redis and Memcached: 697 passed and 1 skipped (the live-server gate), with 100% coverage.

get_client_ip() is now public and exported from fastapi_cachex.session,
and ClientIPDep resolves it with the registered SessionManager's config.
Passing it to create_session() stores the same address the middleware
checks, so sessions created behind a trusted proxy are no longer
rejected on their next request.

Closes #87
@allen0099
allen0099 merged commit cc21021 into master Sep 25, 2026
10 checks passed
@allen0099
allen0099 deleted the feat/public-client-ip branch September 25, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Expose the proxy-aware client IP used for session IP binding

1 participant