defmodule WhoNeedHelpWeb.ClientIp do @moduledoc """ Produces a stable, non-secret rate-limit scope from the client address. `Plug.RewriteOn` populates `conn.remote_ip` from the forwarding header that Caddy sanitizes at the public edge. The PostgreSQL limiter hashes this value before storing it. """ alias Plug.Conn def rate_limit_scope(%Conn{remote_ip: address}) when is_tuple(address) do case :inet.ntoa(address) do value when is_list(value) -> List.to_string(value) _invalid -> "unknown" end end def rate_limit_scope(_conn), do: "unknown" end