mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-05 06:01:24 +02:00
feat: add CF-Connecting-IP as supported real ip header (#2821)
This commit is contained in:
@@ -116,7 +116,7 @@ func NewFlagSet() *pflag.FlagSet {
|
||||
flagSet := pflag.NewFlagSet("oauth2-proxy", pflag.ExitOnError)
|
||||
|
||||
flagSet.Bool("reverse-proxy", false, "are we running behind a reverse proxy, controls whether headers like X-Real-Ip are accepted")
|
||||
flagSet.String("real-client-ip-header", "X-Real-IP", "Header used to determine the real IP of the client (one of: X-Forwarded-For, X-Real-IP, X-ProxyUser-IP, or X-Envoy-External-Address)")
|
||||
flagSet.String("real-client-ip-header", "X-Real-IP", "Header used to determine the real IP of the client (one of: X-Forwarded-For, X-Real-IP, X-ProxyUser-IP, X-Envoy-External-Address, or CF-Connecting-IP)")
|
||||
flagSet.StringSlice("trusted-ip", []string{}, "list of IPs or CIDR ranges to allow to bypass authentication. WARNING: trusting by IP has inherent security flaws, read the configuration documentation for more information.")
|
||||
flagSet.Bool("force-https", false, "force HTTPS redirect for HTTP requests")
|
||||
flagSet.String("redirect-url", "", "the OAuth Redirect URL. ie: \"https://internalapp.yourcompany.com/oauth2/callback\"")
|
||||
|
||||
@@ -16,7 +16,9 @@ func GetRealClientIPParser(headerKey string) (ipapi.RealClientIPParser, error) {
|
||||
case http.CanonicalHeaderKey("X-Forwarded-For"),
|
||||
http.CanonicalHeaderKey("X-Real-IP"),
|
||||
http.CanonicalHeaderKey("X-ProxyUser-IP"),
|
||||
http.CanonicalHeaderKey("X-Envoy-External-Address"):
|
||||
http.CanonicalHeaderKey("X-Envoy-External-Address"),
|
||||
// Cloudflare specific Real-IP header
|
||||
http.CanonicalHeaderKey("CF-Connecting-IP"):
|
||||
return &xForwardedForClientIPParser{header: headerKey}, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -22,6 +22,7 @@ func TestGetRealClientIPParser(t *testing.T) {
|
||||
{"X-REAL-IP", "", forwardedForType},
|
||||
{"x-proxyuser-ip", "", forwardedForType},
|
||||
{"x-envoy-external-address", "", forwardedForType},
|
||||
{"cf-connecting-ip", "", forwardedForType},
|
||||
{"", "the http header key () is either invalid or unsupported", nil},
|
||||
{"Forwarded", "the http header key (Forwarded) is either invalid or unsupported", nil},
|
||||
{"2#* @##$$:kd", "the http header key (2#* @##$$:kd) is either invalid or unsupported", nil},
|
||||
|
||||
Reference in New Issue
Block a user