oauth2-proxy/docs
Georgi Georgiev 08ce94d1c0 security: harden X-Forwarded-For parsing against spoofing
The real-client-IP lookup used by the --trusted-ip auth-bypass allowlist
blindly trusted the leftmost value in X-Forwarded-For (or other
configured --real-client-ip-header). When trusting X-Forwarded-For (which
is the only header set by AWS ALB for example) the connecting peer's
address is appended to X-Forwarded-For rather than replacing the header,
and a client could set X-Forwarded-For to an allowlisted IP and have it
trusted regardless of who actually connected to the proxy.

The parser now walks the hop chain from the newest (rightmost) entry
inward, skipping hops that are themselves trusted proxies, and returns
the first entry that isn't. If the direct connecting peer isn't itself a
trusted proxy, the header is ignored entirely. This reuses the existing
--trusted-proxy-ip configuration, so behavior for deployments that leave
it unset (today's documented trust-all default) is unchanged.

Signed-off-by: Georgi Georgiev <310867+chutzimir@users.noreply.github.com>
2026-07-21 03:53:36 +09:00
..
docs security: harden X-Forwarded-For parsing against spoofing 2026-07-21 03:53:36 +09:00
src/css Microsoft Entra ID provider (#2390) 2024-12-31 11:46:13 +00:00
static doc: readme overhaul and azure sponsorship (#2826) 2024-10-27 12:12:46 +00:00
versioned_docs release v7.15.3 (#3450) 2026-06-09 13:28:24 +02:00
versioned_sidebars release v7.15.0 (#3378) 2026-03-19 01:10:21 +08:00
.gitignore docs: restructure all options and flags (#2747) 2024-08-20 10:40:27 +02:00
README.md doc: SourceHut documentation fixes (#3170) 2025-08-20 12:02:32 +02:00
babel.config.js Migrate existing documentation to Docusaurus 2020-11-05 15:36:27 +00:00
docusaurus.config.js docs: update slack reference for CNCF 2026-06-09 13:50:16 +02:00
package.json release v7.15.2 (#3413) 2026-04-14 13:12:28 +02:00
sidebars.js docs: split integration.md into separate integration guides (#3299) 2026-01-16 09:37:52 +01:00
versions.json release v7.15.0 (#3378) 2026-03-19 01:10:21 +08:00

README.md

Website

This website is built using Docusaurus 2, a modern static website generator.

Installation

npm install

Local Development

npm start

This command starts a local development server and open up a browser window. Most changes are reflected live without having to restart the server.

Build

npm run build

This command generates static content into the build directory and can be served using any static contents hosting service.

Deployment

GIT_USER=<Your GitHub username> USE_SSH=true npm deploy

If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.