- The server endpoint must be a plain host name or IP address. It is
written into client configs as is, so a newline could add lines such
as PreUp, which wg-quick runs as root on the client.
- Listen addresses and the session length (1–720 hours) are checked.
Before web settings or a restore are saved, the server tries the new
listen addresses and certificate files, so a value it cannot start
with is refused instead of stopping the service at the next restart.
- Kernel applies run one at a time and read the config once it is
their turn, so an older config can no longer be applied last.
- Pending passkey sign-ins are capped: 10 per address, 1000 in total.
- Behind a local proxy, the last X-Forwarded-For entry is the client;
earlier ones come from the client and are ignored.
- With LAN access off, peers are also kept from the IPv6 networks on
the uplink, not only from its private IPv4 networks.
- A change that leaves no user with a password is refused, and so is a
backup without one or from a newer version.
Every argon2 run takes 64 MiB and nothing limited how many ran at once,
so parallel sign-in attempts could run the server out of memory (8 at
once used about 600 MB). At most two now run at once; at most 16
sign-ins wait for one, more get HTTP 429. 30 parallel sign-ins peaked
at 275 MB.
A sign-in attempt now counts toward the lockout before its password is
checked, so parallel attempts cannot get past it; a right password
takes its own attempt back. IPv6 addresses are locked out by /64.