properly pick the X-Forwarded-For header for the rate limiter

This was getting 127.0.0.1 for everything.

Merge request reports

Loading