check that the person has access to this resource
return an identifier for the client, looking for 127.0.0.1 and X-Forwarded-For
Return true if the address is of a domain that is trusted by the server. For example, if "X-Forwarded-For" is found in the headers, we will trust it.