httpd icon indicating copy to clipboard operation
httpd copied to clipboard

mod_remoteip: clear incoming RemoteIPProxiesHeader by default

Open erkia opened this issue 3 years ago • 1 comments

RemoteIPProxiesHeader can be used to collect addresses of intermediate trusted proxies. Unfortunately, it is impossible to distinguish, if this header was set by mod_remoteip (can be trusted) or was set in a direct request, which did not pass any trusted proxies.

This change makes sure that RemoteIPProxiesHeader, if configured, is only set by mod_remoteip and is cleared for any requests, that do not come from trusted proxy.

erkia avatar Nov 07 '22 13:11 erkia

Did you try RequestHeader unset headername early to unset the header before processing takes place?

AlexAT avatar Nov 18 '23 07:11 AlexAT