The real-client-IP lookup used by the --trusted-ip auth-bypass allowlist
blindly trusted the leftmost value in X-Forwarded-For (or other
configured --real-client-ip-header). When trusting X-Forwarded-For (which
is the only header set by AWS ALB for example) the connecting peer's
address is appended to X-Forwarded-For rather than replacing the header,
and a client could set X-Forwarded-For to an allowlisted IP and have it
trusted regardless of who actually connected to the proxy.
The parser now walks the hop chain from the newest (rightmost) entry
inward, skipping hops that are themselves trusted proxies, and returns
the first entry that isn't. If the direct connecting peer isn't itself a
trusted proxy, the header is ignored entirely. This reuses the existing
--trusted-proxy-ip configuration, so behavior for deployments that leave
it unset (today's documented trust-all default) is unchanged.
Signed-off-by: Georgi Georgiev <310867+chutzimir@users.noreply.github.com>
* fix: handle Unix socket RemoteAddr in IP resolution
When oauth2-proxy listens on a Unix socket, Go sets RemoteAddr to "@"
instead of the usual "host:port" format. This caused net.SplitHostPort
to fail on every request, flooding logs with errors:
Error obtaining real IP for trusted IP list: unable to get ip and
port from http.RemoteAddr (@)
Fix by handling the "@" RemoteAddr at the source in getRemoteIP,
returning nil without error since Unix sockets have no meaningful
client IP. Also simplify the isTrustedIP guard and add a nil check
in GetClientString to prevent calling String() on nil net.IP.
Fixes#3373
Signed-off-by: h1net <ben@freshdevs.com>
* docs: add changelog entry and Unix socket trusted IPs documentation
Add changelog entry for #3374. Document that trusted IPs cannot match
against RemoteAddr for Unix socket listeners since Go sets it to "@",
and that IP-based trust still works via X-Forwarded-For with reverse-proxy.
Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: h1net <ben@freshdevs.com>
* doc: fix changelog entry for #3374
Signed-off-by: Jan Larwig <jan@larwig.com>
* doc: add trusted ip a section to versioned docs as well
Signed-off-by: Jan Larwig <jan@larwig.com>
---------
Signed-off-by: h1net <ben@freshdevs.com>
Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Jan Larwig <jan@larwig.com>