Closed jpschewe closed 8 months ago
It would be nice if the access logs could display this as well.
The authentication doesn't check by IP, only by username, so no need for forward header support there.
The access log code already has the X-Forwarded-For parameter in it's output.
Check for HTTP forwarded headers when checking for brute force stacks.