Installing: explain the X-Forwarded-For requirement for the reverse proxy
The public unblock page trusts the last X-Forwarded-For element from a
loopback peer as the visitor's address; a proxy that passes a client
header through, or a second CDN hop, lets a visitor forge it and lift
another address's ban. Document the safe directive and the traps.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Uq3zNNmBZdZxfZis4Auc9h
Signed-off-by: Robin <git@lrob.net>