mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
fix(gateway): only trust the client ip header when enabled (#2352)
This commit is contained in:
@@ -56,7 +56,8 @@ env_proxy_config() ->
|
||||
#{
|
||||
<<"client_ip_header">> => env_binary(
|
||||
"FLUXER_CLIENT_IP_HEADER_NAME", <<"x-forwarded-for">>
|
||||
)
|
||||
),
|
||||
<<"trust_client_ip_header">> => env_bool("FLUXER_TRUST_CLIENT_IP_HEADER", false)
|
||||
}.
|
||||
|
||||
-spec env_services_config() -> map().
|
||||
@@ -213,6 +214,7 @@ build_core_config(Service, Internal, Nats, Proxy) ->
|
||||
port => get_int(Service, <<"port">>, 8080),
|
||||
gateway_role => normalize_gateway_role(get_value(Service, <<"gateway_role">>)),
|
||||
client_ip_header => get_binary(Proxy, <<"client_ip_header">>, <<"x-forwarded-for">>),
|
||||
trust_client_ip_header => get_bool(Proxy, <<"trust_client_ip_header">>, false),
|
||||
api_internal_url => get_binary(Internal, <<"api">>, <<"http://127.0.0.1:8088">>),
|
||||
api_rpc_endpoint => get_optional_binary(Service, <<"api_rpc_endpoint">>),
|
||||
nats_core_url => get_string(Nats, <<"core_url">>, "nats://127.0.0.1:4222"),
|
||||
|
||||
@@ -292,6 +292,13 @@ dispatch_after_rate_limit({rate_limited, RLState}, _OpAtom, _Payload) ->
|
||||
|
||||
-spec extract_client_ip(cowboy_req:req()) -> binary().
|
||||
extract_client_ip(Req) ->
|
||||
case fluxer_gateway_env:get(trust_client_ip_header) of
|
||||
true -> extract_trusted_client_ip(Req);
|
||||
_ -> peer_ip_to_binary(cowboy_req:peer(Req))
|
||||
end.
|
||||
|
||||
-spec extract_trusted_client_ip(cowboy_req:req()) -> binary().
|
||||
extract_trusted_client_ip(Req) ->
|
||||
ClientIpHeader = client_ip_header(),
|
||||
case cowboy_req:header(ClientIpHeader, Req) of
|
||||
undefined -> peer_ip_to_binary(cowboy_req:peer(Req));
|
||||
|
||||
Reference in New Issue
Block a user