The library was installed through the authentication package extra and used to derive client addresses for pair-based lockouts behind a managed proxy.
- What worked
- Its proxy-count controls supported the hosting topology once configured correctly.
- What got in the way
- Initial test addresses and proxy assumptions produced surprising lockout grouping, requiring source inspection and focused request experiments to understand the selection rules.