diff --git a/src/interfaces/api/handlers/auth_handler.rs b/src/interfaces/api/handlers/auth_handler.rs index 1261558e..64556952 100644 --- a/src/interfaces/api/handlers/auth_handler.rs +++ b/src/interfaces/api/handlers/auth_handler.rs @@ -290,10 +290,7 @@ pub async fn login( // same account from a different address (issue #323). The check runs // BEFORE Argon2 to save CPU under brute-force attacks. let client_ip = client_ip_from_parts(&headers, Some(peer), false); - if let Err(lockout_secs) = auth_service - .login_lockout - .check(&dto.username, &client_ip) - { + if let Err(lockout_secs) = auth_service.login_lockout.check(&dto.username, &client_ip) { tracing::warn!( target: "audit", event = "auth.login", diff --git a/src/interfaces/middleware/trusted_proxy.rs b/src/interfaces/middleware/trusted_proxy.rs index 0330e10d..d6bb6310 100644 --- a/src/interfaces/middleware/trusted_proxy.rs +++ b/src/interfaces/middleware/trusted_proxy.rs @@ -158,9 +158,7 @@ pub fn client_ip_from_parts( if let Some(peer_addr) = peer { if is_trusted_proxy(peer_addr.ip()) { // Try X-Forwarded-For first (leftmost = original client) - if let Some(xff) = headers - .get("x-forwarded-for") - .and_then(|v| v.to_str().ok()) + if let Some(xff) = headers.get("x-forwarded-for").and_then(|v| v.to_str().ok()) && let Some(ip) = xff .split(',') .next()