Trust the single nginx reverse-proxy hop (confirmed in deploy.md) so
express-rate-limit's per-client bucketing on POST /admin/login sees the
real client IP instead of nginx's. Also fix a dead cookieSecure check
(NODE_ENV === 'secure' never matched) so the session cookie actually
gets Secure in production, verified live with X-Forwarded-Proto: https.
Co-Authored-By:
Claude Sonnet 5 <noreply@anthropic.com>
| Name |
Last commit
|
Last update |
|---|---|---|
| app | Loading commit data... | |
| config | Loading commit data... | |
| docs/superpowers | Loading commit data... | |
| log | Loading commit data... | |
| public | Loading commit data... | |
| .bowerrc | Loading commit data... | |
| .csslintrc | Loading commit data... | |
| .dockerignore | Loading commit data... | |
| .editorconfig | Loading commit data... | |
| .env.example | Loading commit data... | |
| .gitignore | Loading commit data... | |
| .jshintrc | Loading commit data... | |
| CLAUDE.md | Loading commit data... | |
| Dockerfile | Loading commit data... | |
| LICENSE.md | Loading commit data... | |
| MGP_Merchant_Interface_V1.4.7VN.md | Loading commit data... | |
| README.md | Loading commit data... | |
| bower.json | Loading commit data... | |
| deploy.md | Loading commit data... | |
| docker-compose.yml | Loading commit data... | |
| gruntfile.js | Loading commit data... | |
| karma.conf.js | Loading commit data... | |
| package-lock.json | Loading commit data... | |
| package.json | Loading commit data... | |
| server.js | Loading commit data... |