[13:42:05] hi there. I would like to configure an IP restriction for my OAuth1.0a client, which is running on toolforge, to improve its security. Does anyone know where I can find the egress IP addresses that toolforge uses when accessing wikimedia projects? Thank you in advance. [13:43:30] I'm having trouble following how that would work [13:44:13] the user connects from outside to toolforge and then toolforge uses API with oauth to connect to Wikipedia? [13:44:29] which evil request are you worried about? [14:01:32] I think https://wikitech.wikimedia.org/wiki/Help:Cloud_VPS_IP_space has the information you’re looking for [14:02:11] note that the IP space sometimes changes – IMHO putting those IP addresses into the OAuth consumer isn’t a great idea for that reason [14:06:17] @jeremy_b I believe the idea is that the OAuth consumer can’t be used outside Toolforge, so if someone steals the OAuth consumer secret, it somewhat limits their ability to abuse it [14:06:59] (though it doesn’t limit it by *that* much… Toolforge access isn’t too hard to get, and then the attacker can proxy their traffic through there, I believe) [17:51:29] It might help protect you if you accidentally commit your credentials to git, for example, but yeah the risk of breakage is a lot higher so generally not recommended