{"_id":"@chubbyts/chubbyts-undici-trusted-proxy","_rev":"3-9413bc11b40b97a6fe6e2c9b0915e368","name":"@chubbyts/chubbyts-undici-trusted-proxy","dist-tags":{"latest":"1.2.0"},"versions":{"1.0.0":{"name":"@chubbyts/chubbyts-undici-trusted-proxy","version":"1.0.0","keywords":["chubbyts","undici","middleware","trusted-proxy","x-forwarded-for","x-forwarded-proto","x-forwarded-host","client-ip","reverse-proxy"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-trusted-proxy@1.0.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"e1dd676cc24032d7e14d1c9cf3412c962fb34f58","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-trusted-proxy/-/chubbyts-undici-trusted-proxy-1.0.0.tgz","fileCount":7,"integrity":"sha512-YsNcbMpLyynlYnTvxQrQ3ShMavDferHc5xBctw2FOIeF4FTJjeNn6XjUnlJHb5QPmKeIiL2KlRFf9B4aHzDIWQ==","signatures":[{"sig":"MEUCIHY7YxcRobAzbRF+joLd/4eeKuAVkVMJj5CKCGCT1MVYAiEA+CkL4vxrumou3ZHovWUj4+TUZc0eQtl00hcJ1O3i5gI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25871},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts","infection":"stryker run"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-trusted-proxy","type":"git"},"description":"A trusted proxy middleware for chubbyts-undici-server: resolves the client ip, scheme and host from forwarded headers.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0","@chubbyts/chubbyts-dic-config-factory":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@chubbyts/chubbyts-dic-config":"^2.3.0","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-trusted-proxy_1.0.0_1788043140387_0.46580106342350347","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@chubbyts/chubbyts-undici-trusted-proxy","version":"1.1.0","keywords":["chubbyts","undici","middleware","trusted-proxy","x-forwarded-for","x-forwarded-proto","x-forwarded-host","client-ip","reverse-proxy"],"author":"Dominik Zogg","license":"MIT","_id":"@chubbyts/chubbyts-undici-trusted-proxy@1.1.0","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"dist":{"shasum":"610422fbc9c97619ae9807418b74768d6416b8a3","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-trusted-proxy/-/chubbyts-undici-trusted-proxy-1.1.0.tgz","fileCount":7,"integrity":"sha512-FXXraQ7Tt+0ZpFS4WIepkyu2QmjrC8Fs2b9SMNCyRZqnB8fvdt/Bm4fHhdRLX/jo6qb57EWx6/ynVogVPxv8iQ==","signatures":[{"sig":"MEYCIQDx+Pkj9fGnymutT5/I6qLpE7hA1RCG3CS8wU27saqKeQIhAL5TjeUN8kIA1TeyQx6RX+szvOFWM6/Ox80E4+VCBAVY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27953},"type":"module","engines":{"node":">=22"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"scripts":{"cs":"prettier --check src tests","lint":"oxlint src tests vitest.config.ts","test":"vitest","build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","lint-fix":"oxlint --fix src tests vitest.config.ts","infection":"stryker run"},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"prettier":{"tabWidth":2,"printWidth":120,"singleQuote":true,"trailingComma":"all"},"repository":{"url":"chubbyts/chubbyts-undici-trusted-proxy","type":"git"},"description":"A trusted proxy middleware for chubbyts-undici-server: resolves the client ip, scheme and host from forwarded headers.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0","@chubbyts/chubbyts-dic-config-factory":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxlint":"^1.77.0","vitest":"^4.1.10","prettier":"^3.9.6","typescript":"^7.0.2","@types/node":"^26.1.2","@vitest/coverage-v8":"^4.1.10","@stryker-mutator/core":"^9.6.1","@chubbyts/chubbyts-oxlint":"^1.0.1","@chubbyts/chubbyts-dic-config":"^2.3.0","@stryker-mutator/vitest-runner":"^9.6.1","@chubbyts/chubbyts-function-mock":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/chubbyts-undici-trusted-proxy_1.1.0_1788465972938_0.5395759828084499","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@chubbyts/chubbyts-undici-trusted-proxy","type":"module","version":"1.2.0","description":"A trusted proxy middleware for chubbyts-undici-server: resolves the client ip, scheme and host from forwarded headers.","keywords":["chubbyts","undici","middleware","trusted-proxy","x-forwarded-for","x-forwarded-proto","x-forwarded-host","client-ip","reverse-proxy"],"author":"Dominik Zogg","license":"MIT","repository":{"type":"git","url":"chubbyts/chubbyts-undici-trusted-proxy"},"prettier":{"printWidth":120,"tabWidth":2,"singleQuote":true,"trailingComma":"all"},"exports":{"./*":{"types":"./*.d.ts","import":"./*.js","default":"./*.js"}},"engines":{"node":">=22"},"dependencies":{"@chubbyts/chubbyts-dic-config-factory":"^1.0.0","@chubbyts/chubbyts-dic-types":"^2.3.0","@chubbyts/chubbyts-undici-server":"^1.2.0"},"devDependencies":{"@chubbyts/chubbyts-dic-config":"^2.3.0","@chubbyts/chubbyts-function-mock":"^2.3.0","@chubbyts/chubbyts-oxlint":"^1.0.1","@stryker-mutator/core":"^9.6.1","@stryker-mutator/vitest-runner":"^9.6.1","@types/node":"^26.1.2","@vitest/coverage-v8":"^4.1.10","oxlint":"^1.77.0","prettier":"^3.9.6","typescript":"^7.0.2","vitest":"^4.1.10"},"publishConfig":{"access":"public"},"scripts":{"build":"rm -Rf dist && tsc","cs-fix":"prettier --write src tests","cs":"prettier --check src tests","infection":"stryker run","lint-fix":"oxlint --fix src tests vitest.config.ts","lint":"oxlint src tests vitest.config.ts","test":"vitest"},"_nodeVersion":"24.16.0","_id":"@chubbyts/chubbyts-undici-trusted-proxy@1.2.0","dist":{"integrity":"sha512-s/LyP8mlmlVI5TJZtl3bxbhqgNz1TYgL7Esvb84TIU2urEIz80NSN3ni7CB+js+jVo6Yt8PvXAAe4rQjo9yzyQ==","shasum":"734e1bb100578007d0f1337a7a487bc25a53aa42","tarball":"https://registry.npmjs.org/@chubbyts/chubbyts-undici-trusted-proxy/-/chubbyts-undici-trusted-proxy-1.2.0.tgz","fileCount":7,"unpackedSize":36016,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCQar3VT4cBDSo52VL6gMstFDCKthRGHRg8Hj9SjnsUlQIhANGsr1Jjm3WMwK7wix0h4RaGQOoMJGqWqn4esaYgm730"}]},"_npmUser":{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"},"directories":{},"maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/chubbyts-undici-trusted-proxy_1.2.0_1788711486232_0.654532557925358"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-29T22:39:00.290Z","modified":"2026-09-06T16:18:06.556Z","1.0.0":"2026-08-29T22:39:00.528Z","1.1.0":"2026-09-03T20:06:13.079Z","1.2.0":"2026-09-06T16:18:06.371Z"},"author":"Dominik Zogg","license":"MIT","keywords":["chubbyts","undici","middleware","trusted-proxy","x-forwarded-for","x-forwarded-proto","x-forwarded-host","client-ip","reverse-proxy"],"repository":{"type":"git","url":"chubbyts/chubbyts-undici-trusted-proxy"},"description":"A trusted proxy middleware for chubbyts-undici-server: resolves the client ip, scheme and host from forwarded headers.","maintainers":[{"name":"dominikzogg","email":"dominik.zogg@ikmail.com"}],"readme":"# chubbyts-undici-trusted-proxy\n\n[![CI](https://github.com/chubbyts/chubbyts-undici-trusted-proxy/actions/workflows/ci.yml/badge.svg?branch=master)](https://github.com/chubbyts/chubbyts-undici-trusted-proxy/actions/workflows/ci.yml)\n[![Coverage Status](https://coveralls.io/repos/github/chubbyts/chubbyts-undici-trusted-proxy/badge.svg?branch=master)](https://coveralls.io/github/chubbyts/chubbyts-undici-trusted-proxy?branch=master)\n[![Mutation testing badge](https://img.shields.io/endpoint?style=flat&url=https%3A%2F%2Fbadge-api.stryker-mutator.io%2Fgithub.com%2Fchubbyts%2Fchubbyts-undici-trusted-proxy%2Fmaster)](https://dashboard.stryker-mutator.io/reports/github.com/chubbyts/chubbyts-undici-trusted-proxy/master)\n[![npm-version](https://img.shields.io/npm/v/@chubbyts/chubbyts-undici-trusted-proxy.svg)](https://www.npmjs.com/package/@chubbyts/chubbyts-undici-trusted-proxy)\n\n[![bugs](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=bugs)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![code_smells](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=code_smells)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![coverage](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=coverage)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![duplicated_lines_density](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=duplicated_lines_density)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![ncloc](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=ncloc)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![sqale_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=sqale_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![alert_status](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=alert_status)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![reliability_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=reliability_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![security_rating](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=security_rating)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![sqale_index](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=sqale_index)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n[![vulnerabilities](https://sonarcloud.io/api/project_badges/measure?project=chubbyts_chubbyts-undici-trusted-proxy&metric=vulnerabilities)](https://sonarcloud.io/dashboard?id=chubbyts_chubbyts-undici-trusted-proxy)\n\n## Description\n\nA trusted proxy middleware for chubbyts-undici-server: resolves the client ip, scheme and host from the forwarded\nheaders (`x-forwarded-for`, `x-forwarded-proto`, `x-forwarded-host`) of trusted proxies into request attributes.\n\n## Requirements\n\n * node: 22\n * [@chubbyts/chubbyts-dic-config-factory][5]: ^1.0.0\n * [@chubbyts/chubbyts-dic-types][3]: ^2.3.0\n * [@chubbyts/chubbyts-undici-server][2]: ^1.2.0\n\n## Installation\n\nThrough [NPM](https://www.npmjs.com) as [@chubbyts/chubbyts-undici-trusted-proxy][1].\n\n```ts\nnpm i @chubbyts/chubbyts-undici-trusted-proxy@^1.2.0\n```\n\n## Usage\n\nBehind a reverse proxy (nginx, traefik, a load balancer, ...) the server only sees the proxy, the client data arrives\nwithin the forwarded headers, which any client can send as well. The middleware decides which entries of these headers\nto trust and passes the request on with the `clientIp`, `scheme` and `host` attributes set, so that every other part\n(rate limiting, logging, access control, url generation, ...) reads them from one place instead of parsing headers.\n\n```ts\nimport type { TrustedProxyAttributes } from '@chubbyts/chubbyts-undici-trusted-proxy/dist/middleware';\nimport {\n  DEFAULT_FORWARDED_HEADERS,\n  createForwardedResolver,\n  createTrustedProxyMiddleware,\n} from '@chubbyts/chubbyts-undici-trusted-proxy/dist/middleware';\nimport type { Handler } from '@chubbyts/chubbyts-undici-server/dist/server';\nimport { Response, ServerRequest } from '@chubbyts/chubbyts-undici-server/dist/server';\n\n// the ips / cidrs of the proxies: the entries of x-forwarded-for get walked from the right, the first one not within\n// the ranges is the client (robust against a varying number of hops)\nconst trustedProxyMiddleware = createTrustedProxyMiddleware(createForwardedResolver(['10.0.0.0/8', '::1']));\n\nconst handler: Handler<TrustedProxyAttributes> = async (serverRequest) => {\n  // each one string | undefined: the unresolved ones are undefined\n  const { clientIp, scheme, host } = serverRequest.attributes;\n\n  return new Response(`${clientIp} requested ${scheme}://${host}`);\n};\n\n(async () => {\n  const serverRequest = new ServerRequest<TrustedProxyAttributes, { remoteAddress: string }>('https://example.com', {\n    headers: { 'x-forwarded-for': '203.0.113.1, 10.0.0.1', 'x-forwarded-proto': 'https', 'x-forwarded-host': 'example.com' },\n    // the address of the connection, as set by the server (see security)\n    attributes: { remoteAddress: '10.0.0.2' },\n  });\n\n  const response = await trustedProxyMiddleware(serverRequest, handler);\n})();\n```\n\nRegister the middleware **before** any middleware that reads the attributes. Requests without a resolvable client ip\n(no `x-forwarded-for`, only trusted entries, or a first untrusted entry which is not a valid ip like `unknown` or\n`ip:port`) get `undefined` attributes. The middleware always sets all three attributes (the unresolved ones as\n`undefined`), so that nothing set before it survives. A subnet matching every ip (`0.0.0.0/0`, `::/0`) gets rejected,\nas it would trust every entry and never resolve anything, an empty list as well, as it would trust no entry and resolve\nthe nearest proxy as client ip, the entries get trimmed. Ipv4 mapped ipv6 addresses (`::ffff:10.0.0.1`) match ipv4\nsubnets.\n\nThe `clientIp` gets canonicalized (lowercased and compressed, `2001:DB8:0:0::1` as `2001:db8::1`, ipv4 mapped ipv6\naddresses as ipv4, `::ffff:203.0.113.1` as `203.0.113.1`), so that the same client always resolves to the same string,\nno matter how a hop wrote it (rate limit keys, allowlists, logs). An ipv6 address with a zone id (`fe80::1%eth0`) is\nnot a valid ip.\n\nThe scheme and host get only resolved when a client ip was resolved: the entry at the same position, if the header has\nas many entries as the `x-forwarded-for` header (proxies appending to all of them), the last (the one the nearest proxy\nset) otherwise. The scheme gets lowercased and must be `http` or `https`, the host gets lowercased and must be a\nsyntactically valid host (a hostname, an ipv4 or a bracketed ipv6, each with an optional port from 1 to 65535),\neverything else resolves `undefined`.\n\n### Security\n\nThe trust is anchored at the address of the connection, the `remoteAddress` attribute (a string, `undefined` counts\nas not set, a port gets stripped) as set by the server or a middleware in front, so nothing else may set it (run the\nmiddleware before the router, a route placeholder `{remoteAddress}` would let the client choose it): a connection from\noutside the trusted ranges counts as the client itself, its address is the `clientIp` and the headers get ignored. An\naddress which is not a valid ip (junk, a non string) resolves nothing, the middleware never falls back to the headers.\nA request without any address of the connection resolves nothing (fail closed), as the middleware cannot verify that\nthe last hop was a trusted proxy. Mind that [chubbyts-undici-server][2] itself does not set the attribute: if the\nserver never provides it, disable the check explicitly with the third argument, the server must then not be reachable\nexcept through the proxies:\n\n```ts\ncreateForwardedResolver(['10.0.0.0/8'], DEFAULT_FORWARDED_HEADERS, false);\n```\n\nEither way, the proxies must set (or strip) all the forwarded headers, as any header they do not touch is supplied by\nthe client: a proxy passing the client's `x-forwarded-proto` / `x-forwarded-host` through lets the client choose them,\nthe middleware cannot tell. The `clientIp` is always a valid ip and the `scheme` always `http` or `https`, but the\n`host` is only checked for its syntax: before using it for url generation or redirects, check it against the hosts the\napplication serves (an allowlist), so that a passed through `x-forwarded-host` cannot poison generated urls:\n\n```ts\nconst { host } = serverRequest.attributes;\n\nif (!['example.com', 'www.example.com'].includes(host ?? '')) {\n  return new Response('Bad Request', { status: 400 });\n}\n```\n\nThe RFC 7239 `Forwarded` header (`for=...;proto=...;host=...`) is not supported, only the de-facto `x-forwarded-*`\nheaders (or single value ones like `x-real-ip`, see below): if the proxies send `Forwarded`, configure them to send the\n`x-forwarded-*` headers as well.\n\n### Headers\n\nThe second argument replaces the header names (each one optional, `null` disables `proto` and `host`, `for` cannot be\ndisabled, an invalid header name throws), useful for a proxy setting a single value header like `x-real-ip`:\n\n```ts\ncreateForwardedResolver(['10.0.0.0/8'], { for: 'x-real-ip', proto: 'x-forwarded-proto', host: null });\n```\n\n### Service factories (chubbyts-dic-config)\n\nThe package ships service factories (abstract factories built on [chubbyts-dic-config-factory][5]) for a [chubbyts-dic-config][4] (or any [chubbyts-dic-types][3] compatible) container within `@chubbyts/chubbyts-undici-trusted-proxy/dist/service-factory`, configured through `config.chubbyts.trustedProxy`:\n\n```ts\nimport type { ConfigFactory } from '@chubbyts/chubbyts-dic-config/dist/dic-config';\nimport { createContainerByConfigFactory } from '@chubbyts/chubbyts-dic-config/dist/dic-config';\nimport type { TrustedProxyAttributes } from '@chubbyts/chubbyts-undici-trusted-proxy/dist/middleware';\nimport type { TrustedProxyConfig } from '@chubbyts/chubbyts-undici-trusted-proxy/dist/service-factory';\nimport { trustedProxyMiddlewareServiceFactory } from '@chubbyts/chubbyts-undici-trusted-proxy/dist/service-factory';\nimport type { Middleware } from '@chubbyts/chubbyts-undici-server/dist/server';\n\nconst container = createContainerByConfigFactory({\n  chubbyts: {\n    trustedProxy: {\n      trustedProxies: ['10.0.0.0/8', '::1'],\n      // headers: { for: 'x-forwarded-for', proto: 'x-forwarded-proto', host: 'x-forwarded-host' },\n      // requireRemoteAddress: true,\n    } satisfies TrustedProxyConfig,\n  },\n  dependencies: {\n    factories: new Map<string, ConfigFactory>([['trustedProxyMiddleware', trustedProxyMiddlewareServiceFactory()]]),\n  },\n})();\n\nconst trustedProxyMiddleware = container.get<Middleware<TrustedProxyAttributes>>('trustedProxyMiddleware');\n```\n\nThe `trustedProxyMiddlewareServiceFactory` uses the service `trustedProxyForwardedResolver` of the container if registered, and creates it through the shipped `forwardedResolverServiceFactory` otherwise. Register it under its name to replace it or to share it with other services.\n\n#### With names\n\nTo serve different parts of an application behind different proxies (a public load balancer, an internal one, ...), the same factories can be registered multiple times with a name: the config is then read from `config.chubbyts.trustedProxy.<name>` and the name gets appended to each service id (`trustedProxyMiddlewarepublic`, `trustedProxyForwardedResolverpublic`, ...).\n\n```ts\nconst container = createContainerByConfigFactory({\n  chubbyts: {\n    trustedProxy: {\n      public: { trustedProxies: ['10.0.0.0/8', '::1'] },\n      internal: { trustedProxies: ['192.168.0.0/16'], headers: { for: 'x-real-ip', host: null } },\n    } satisfies Record<string, TrustedProxyConfig>,\n  },\n  dependencies: {\n    factories: new Map<string, ConfigFactory>([\n      ['trustedProxyMiddlewarepublic', trustedProxyMiddlewareServiceFactory('public')],\n      ['trustedProxyMiddlewareinternal', trustedProxyMiddlewareServiceFactory('internal')],\n    ]),\n  },\n})();\n\nconst publicTrustedProxyMiddleware = container.get<Middleware<TrustedProxyAttributes>>('trustedProxyMiddlewarepublic');\nconst internalTrustedProxyMiddleware = container.get<Middleware<TrustedProxyAttributes>>('trustedProxyMiddlewareinternal');\n```\n\n## Copyright\n\n2026 Dominik Zogg\n\n[1]: https://www.npmjs.com/package/@chubbyts/chubbyts-undici-trusted-proxy\n[2]: https://www.npmjs.com/package/@chubbyts/chubbyts-undici-server\n[3]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-types\n[4]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-config\n[5]: https://www.npmjs.com/package/@chubbyts/chubbyts-dic-config-factory\n","readmeFilename":""}