Documentation
¶
Overview ¶
Command gitcorsproxy runs the sovereign CORS git smart-HTTP proxy.
It reads its configuration from flags, each of which falls back to an environment variable:
-listen GITCORSPROXY_LISTEN listen address (default ":8181") -origins GITCORSPROXY_ORIGINS comma-separated allowed browser origins -hosts GITCORSPROXY_HOSTS comma-separated upstream host allowlist -tls-cert GITCORSPROXY_TLS_CERT optional TLS certificate file -tls-key GITCORSPROXY_TLS_KEY optional TLS key file -rate GITCORSPROXY_RATE requests per minute per client IP (default 120) -burst GITCORSPROXY_BURST back-to-back request burst per client IP (default 30) -trusted-hops GITCORSPROXY_TRUSTED_HOPS trusted reverse-proxy hops for XFF (default 1) -max-response-bytes GITCORSPROXY_MAX_RESPONSE_BYTES cap on one relayed response, 0=unlimited (default 1073741824) -timeout GITCORSPROXY_TIMEOUT per-request timeout, 0=none (default 5m0s)
-origins and -hosts are required. TLS is optional: in the sovereign deployment the proxy runs behind Caddy (which terminates Let's Encrypt TLS), so the two TLS flags are only for a standalone bind.
Abuse / DoS hardening ¶
The proxy is publicly reachable and cannot source-restrict (the playground runs in end-users' browsers), so it defends itself:
- -rate/-burst apply a per-client-IP token bucket; over budget → 429 with Retry-After. The client IP is read from X-Forwarded-For counting from the right by -trusted-hops (so a client-forged leftmost XFF cannot spoof the key), falling back to the connection's RemoteAddr.
- -max-response-bytes caps a single relayed response so the proxy cannot be used to shift unbounded bandwidth.
- -timeout bounds the whole proxied request so a slow-loris or hung upstream cannot pin resources.
Click to show internal directories.
Click to hide internal directories.