fix: spoofing of X-Forwarded-For

This commit is contained in:
Henrique Dias
2024-10-21 08:15:19 +02:00
parent 8c49af0b68
commit d500716f29
3 changed files with 20 additions and 11 deletions
+5
View File
@@ -71,6 +71,11 @@ debug: false
# Disable sniffing the files to detect their content type. Default is 'false'. # Disable sniffing the files to detect their content type. Default is 'false'.
noSniff: false noSniff: false
# Whether the server runs behind a trusted proxy or not. When this is true,
# the header X-Forwarded-For will be used for logging the remote addresses
# of logging attempts (if available).
behindProxy: false
# The directory that will be able to be accessed by the users when connecting. # The directory that will be able to be accessed by the users when connecting.
# This directory will be used by users unless they have their own 'directory' defined. # This directory will be used by users unless they have their own 'directory' defined.
# Default is '.' (current directory). # Default is '.' (current directory).
+1
View File
@@ -33,6 +33,7 @@ type Config struct {
Prefix string Prefix string
NoSniff bool NoSniff bool
NoPassword bool NoPassword bool
BehindProxy bool
Log Log Log Log
CORS CORS CORS CORS
Users []User Users []User
+9 -6
View File
@@ -18,6 +18,7 @@ type handlerUser struct {
type Handler struct { type Handler struct {
noPassword bool noPassword bool
behindProxy bool
user *handlerUser user *handlerUser
users map[string]*handlerUser users map[string]*handlerUser
} }
@@ -25,6 +26,7 @@ type Handler struct {
func NewHandler(c *Config) (http.Handler, error) { func NewHandler(c *Config) (http.Handler, error) {
h := &Handler{ h := &Handler{
noPassword: c.NoPassword, noPassword: c.NoPassword,
behindProxy: c.BehindProxy,
user: &handlerUser{ user: &handlerUser{
User: User{ User: User{
UserPermissions: c.UserPermissions, UserPermissions: c.UserPermissions,
@@ -85,7 +87,7 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
w.Header().Set("WWW-Authenticate", `Basic realm="Restricted"`) w.Header().Set("WWW-Authenticate", `Basic realm="Restricted"`)
// Retrieve the real client IP address using the updated helper function // Retrieve the real client IP address using the updated helper function
remoteAddr := getRealRemoteIP(r) remoteAddr := getRealRemoteIP(r, h.behindProxy)
// Gets the correct user for this request. // Gets the correct user for this request.
username, password, ok := r.BasicAuth() username, password, ok := r.BasicAuth()
@@ -166,13 +168,14 @@ func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
} }
// getRealRemoteIP retrieves the client's actual IP address, considering reverse proxies. // getRealRemoteIP retrieves the client's actual IP address, considering reverse proxies.
func getRealRemoteIP(r *http.Request) string { func getRealRemoteIP(r *http.Request, behindProxy bool) string {
ip := r.Header.Get("X-Forwarded-For") if behindProxy {
if ip == "" { if ip := r.Header.Get("X-Forwarded-For"); ip != "" {
ip = r.RemoteAddr
}
return ip return ip
} }
}
return r.RemoteAddr
}
type responseWriterNoBody struct { type responseWriterNoBody struct {
http.ResponseWriter http.ResponseWriter