IP Address Filtering
validate source address requires the request's source address to equal the
addr claim in the accepted token. It is an additional binding check, not a
network allowlist and not proof that a device is trusted.
# Inside an authorization policy:
validate source address
allow roles app/member
The issuer must record the source address. In a portal, enable source ip tracking
enables this token claim. A missing or mismatched claim fails validation.
Configure the issuer and gatekeeper to interpret source addresses consistently.
Behind a reverse proxy, trust only known proxy hops and normalize forwarded headers. Otherwise an arbitrary forwarded address can defeat the intended binding or lock out legitimate users. See deployment diagnostics.
A user's address can change with mobile networks, VPNs, NAT, and IPv4/IPv6 selection. Test those transitions before enabling this rule for a browser application. To restrict a management endpoint to a CIDR, use an appropriate Caddy request matcher rather than this token-equality feature.