A client can prepend a spoofed entry to X-Forwarded-For before the request reaches our load balancer. Taking the first value would return the attacker's address. Since we sit behind a single trusted LB that appends the real client IP as the last entry, switch to rightmost extraction for both X-Forwarded-For and RFC 7239 Forwarded headers. Signed-off-by: Émile Ré <emile@getprobo.com>