nginx: trust X-Forwarded-For only from TRUSTED_PROXIES (closes #64)
check / check (push) Successful in 15s
check / check (push) Successful in 15s
nginx trusted X-Forwarded-For from every RFC1918 address, so a client reaching it from one could write a new address on each request and get a fresh rate-limit allowance. The container's TRUSTED_PROXIES now names the reverse proxies nginx trusts, none by default. bin/entrypoint.sh makes each entry a CIDR, checks it with the new "netwatch-server check-cidr", which runs the server's own TRUSTED_PROXIES parsing, and writes one set_real_ip_from line per entry into /etc/nginx/trusted-proxies.conf, which nginx.conf includes. The backend is started with TRUSTED_PROXIES=127.0.0.1/32, since nginx is its only client. The viewport test mounts an empty file there. Model: opus-5-5
This commit was merged in pull request #68.
This commit is contained in:
+6
-4
@@ -11,10 +11,12 @@ server {
|
||||
root /usr/share/nginx/html;
|
||||
index index.html;
|
||||
|
||||
# Trust RFC1918 reverse proxies for X-Forwarded-For
|
||||
set_real_ip_from 10.0.0.0/8;
|
||||
set_real_ip_from 172.16.0.0/12;
|
||||
set_real_ip_from 192.168.0.0/16;
|
||||
# The client address comes from X-Forwarded-For only on a request
|
||||
# from the reverse proxies in TRUSTED_PROXIES: bin/entrypoint.sh
|
||||
# writes one set_real_ip_from line for each into this file, and
|
||||
# leaves it empty when TRUSTED_PROXIES is unset, so that by default
|
||||
# the client address is the one each request comes from.
|
||||
include /etc/nginx/trusted-proxies.conf;
|
||||
real_ip_header X-Forwarded-For;
|
||||
real_ip_recursive on;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user