Hanyuu should:
- Verify that incoming signatures from the headers
X-Radio-Client
andX-Radio-Auth
match. (see below) - Use
X-Forwarded-For
on signature mismatch (or check remote addr). (this means that signatures are not needed for the current site) - return "hmac error" after we migrate websites on hmac failure