Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

HTTP_X_FORWARDED_FOR ignored if REMOTE_ADDR is "trusted"

#2126

Rails breaks HTTP_X_FORWARDED_FOR for proxies that are not on a class-C net. This is common for sites that use a transparent firewall that don't use a DMZ-style, NAT-based network topology, but where each node has a public IP.

This means the proxy's legitimate HTTP_X_FORWARDED_FOR header is simply ignored, and the proxy's own IP is returned. Nicely done.

In our case, every machine in the cluster is identically configured and capable of being a proxy. Therefore, our only option is to modify TRUSTED_PROXIES at runtime to include the correct IP range. That's an ugly solution, and the proper solution might be to replace the constant with a freely modifiable list.

Reported by Alexander Staubo · March 4th, 2009 @ 01:46 PM

State: resolved
Milestone: none
Assigned to: nobody
Importance: none

Activity

  1. CancelProfileIsBroken
    CancelProfileIsBroken
    • Tag changed from proxy, request to bugmash, proxy, request

    August 5th, 2009 @ 02:27 PM

  2. Elise Huard
    Elise Huard

    if i understand correctly, the problem occurs in the remote_ip method of the Request class (actionpack/lib/action_dispatch/http/request.rb).
    The fact that the proxies' address is not a local network address (as determined by TRUSTED_PROXIES), but a public one, adds it to the HTTP_X_FORWARDED_FOR, and so this becomes the returned remote ip address - which makes the latter pretty useless.
    I'm going to have a look at a possible solution.

    August 9th, 2009 @ 12:13 PM

  3. Felipe Talavera
    Felipe Talavera

    Here, it's the patch with the test.

    Finally, I addeed the ActionController::Base.local_trusted_proxies config option that can be set with a regex to match the TRUSTED_PROXIES with a public ip.

    August 9th, 2009 @ 01:18 PM

  4. Rizwan Reza
    Rizwan Reza

    verified

    +1 This patch applies cleanly to 2-3-stable. All tests pass.

    August 9th, 2009 @ 04:01 PM

  5. Felipe Talavera
    Felipe Talavera

    Oks, here the version prepared for master.

    August 9th, 2009 @ 04:23 PM

  6. Rizwan Reza
    Rizwan Reza

    verified

    +1 The second patch applies cleanly to master and tests also pass. Good work!

    August 9th, 2009 @ 04:30 PM

  7. Repository
    Repository
    • State changed from new to resolved

    (from [654568e71b1ee36a04acef74b1a8ce4737050882]) Allow to configure trusted proxies via ActionController::Base.trusted_proxies [#2126 HTTP_X_FORWARDED_FOR ignored if REMOTE_ADDR is "trusted" state:resolved]

    Signed-off-by: Pratik Naik pratiknaik@gmail.com
    http://github.com/rails/rails/commit/654568e71b1ee36a04acef74b1a8ce...

    August 9th, 2009 @ 04:58 PM

  8. CancelProfileIsBroken
    CancelProfileIsBroken
    • Tag changed from bugmash, proxy, request to proxy, request
    • Milestone cleared.

    August 9th, 2009 @ 05:13 PM