This project is archived and is in readonly mode.
HTTP_X_FORWARDED_FOR ignored if REMOTE_ADDR is "trusted"
-
CancelProfileIsBroken
- Tag changed from proxy, request to bugmash, proxy, request
-
Elise Huard
if i understand correctly, the problem occurs in the remote_ip method of the Request class (actionpack/lib/action_dispatch/http/request.rb).
The fact that the proxies' address is not a local network address (as determined by TRUSTED_PROXIES), but a public one, adds it to the HTTP_X_FORWARDED_FOR, and so this becomes the returned remote ip address - which makes the latter pretty useless.
I'm going to have a look at a possible solution. -
Felipe Talavera
Here, it's the patch with the test.
Finally, I addeed the ActionController::Base.local_trusted_proxies config option that can be set with a regex to match the TRUSTED_PROXIES with a public ip.
-
Rizwan Reza
verified
+1 This patch applies cleanly to 2-3-stable. All tests pass.
-
Felipe Talavera
Oks, here the version prepared for master.
-
Rizwan Reza
verified
+1 The second patch applies cleanly to master and tests also pass. Good work!
-
Repository
- State changed from new to resolved
(from [654568e71b1ee36a04acef74b1a8ce4737050882]) Allow to configure trusted proxies via ActionController::Base.trusted_proxies [#2126 HTTP_X_FORWARDED_FOR ignored if REMOTE_ADDR is "trusted" state:resolved]
Signed-off-by: Pratik Naik pratiknaik@gmail.com
http://github.com/rails/rails/commit/654568e71b1ee36a04acef74b1a8ce... -
CancelProfileIsBroken
- Tag changed from bugmash, proxy, request to proxy, request
- Milestone cleared.
