oauth2-proxy/docs/versioned_docs
H1net a4d89036ec
fix: handle Unix socket RemoteAddr in IP resolution (#3374)
* fix: handle Unix socket RemoteAddr in IP resolution

When oauth2-proxy listens on a Unix socket, Go sets RemoteAddr to "@"
instead of the usual "host:port" format. This caused net.SplitHostPort
to fail on every request, flooding logs with errors:

  Error obtaining real IP for trusted IP list: unable to get ip and
  port from http.RemoteAddr (@)

Fix by handling the "@" RemoteAddr at the source in getRemoteIP,
returning nil without error since Unix sockets have no meaningful
client IP. Also simplify the isTrustedIP guard and add a nil check
in GetClientString to prevent calling String() on nil net.IP.

Fixes #3373

Signed-off-by: h1net <ben@freshdevs.com>

* docs: add changelog entry and Unix socket trusted IPs documentation

Add changelog entry for #3374. Document that trusted IPs cannot match
against RemoteAddr for Unix socket listeners since Go sets it to "@",
and that IP-based trust still works via X-Forwarded-For with reverse-proxy.

Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: h1net <ben@freshdevs.com>

* doc: fix changelog entry for #3374

Signed-off-by: Jan Larwig <jan@larwig.com>

* doc: add trusted ip a section to versioned docs as well

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: h1net <ben@freshdevs.com>
Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
2026-03-23 10:22:36 +01:00
..
version-7.0.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.1.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.2.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.3.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.4.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.5.x doc: improved clarity and correctness of proxy behaviour (#3305) 2026-01-14 21:26:50 +01:00
version-7.6.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.7.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.8.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.9.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.10.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.11.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.12.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.13.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.14.x doc: add missing redis-ca-path documentation (#3341) 2026-03-18 22:46:31 +08:00
version-7.15.x fix: handle Unix socket RemoteAddr in IP resolution (#3374) 2026-03-23 10:22:36 +01:00