Skip to content

Don't require proxy ip to use X-Forwarded-For header - #104

Open
ii8 wants to merge 1 commit into
emikulic:masterfrom
ii8:master
Open

Don't require proxy ip to use X-Forwarded-For header#104
ii8 wants to merge 1 commit into
emikulic:masterfrom
ii8:master

Conversation

@ii8

@ii8 ii8 commented Aug 16, 2026

Copy link
Copy Markdown

The existing "--trusted-ip" option only allows setting a single IP meaning it does not work with multiple reverse proxies which is quite a common setup.

Furthermore it's not relevant that the proxy IP is trusted because as implemented in darkhttpd the first value from the X-Forwarded-For header is used which is untrusted in any case. If you wanted a value from the X-Forwarded-For header(s) along with knowledge that it was put there by your own proxy you have to combine all the headers and parse values from the right, skipping only your own proxy IPs and taking the first from "outside". The first value from the left can be spoofed easily, it's ok here because we only use it for logging, but it's irrelevant whether the proxy ip is "trusted".

Another benefit of this approach is that we don't have to compare IP addresses.

No release has been made with the --trusted-ip option so I'm assuming it's ok to make a breaking change like this

@emikulic

Copy link
Copy Markdown
Owner

I don't really have an opinion on this functionality. @Jipok, what do you think? You added this feature in #88

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants