Security: the visitor's address is decided by the web server; a random database password
Without a trusted proxy in front (TRUST_PROXY), X-Forwarded-For and X-Real-IP from the visitor are replaced by the connection's own address, so the api's per-visitor limits (sign-in attempts, feedback) cannot be sidestepped. Behind Caddy or nginx the proxy's last entry is used. init-env.ts now also generates POSTGRES_PASSWORD for docker compose. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
数
数字生命卡兹克 committed
589f79eff09470b31ba8a7f1d9eb62d36ff2be6c
Parent: 877d6d5