Skip to content

Respect Forwarding Headers - #71

Merged
adeutscher merged 6 commits into
developfrom
issue/68/forwarded-headers-options
Sep 14, 2026
Merged

adeutscher merged 6 commits into
developfrom
issue/68/forwarded-headers-options

Conversation

@adeutscher

Copy link
Copy Markdown
Owner

Set up API to respect origin headers such as X-Forwarded-For, X-Forwarded-Proto, X-Forwarded-Prefix from trusted proxy IP addresses.

These changes make our original setting of a path base obsolete, so that setting has been removed. Respecting the X-Forwarded-Prefix header is much more flexible.

Tests run:

  • API confirms the values passed along by X-Forwarded-Host and X-Forwarded-Prefix, both when the trusted network was a really wide-reaching CIDR and when the trusted network was a really tightly scoped /32 address.
  • If the trusted network is set to the proxy address, then the observed client IP address is that of the original client by way of the X-Forwarded-For header (confirmed using HttpContext.Connection.RemoteIpAddress)
  • If the trusted network is set to include the proxy address, then two different original clients get independent rate limits.
  • If the trusted network not set to include the proxy, then the observed IP address is that of the proxy.
  • If the trusted network not set to include the proxy, then it looks like X-Forwarded-Host is still respected (X-Forwarded-Prefix is not). This makes sense because the X-Forwarded-Host header isn't making any direct statements about who is making the original request.
  • If respecting headers is disabled, then the observed IP address of a request through the proxy is that of the proxy.

@adeutscher adeutscher self-assigned this Sep 14, 2026
@adeutscher adeutscher added the enhancement New feature or request label Sep 14, 2026
@adeutscher
adeutscher merged commit d03f68d into develop Sep 14, 2026
1 check passed
@adeutscher
adeutscher deleted the issue/68/forwarded-headers-options branch September 14, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm rate limiting is Proxy-Aware Configure ForwardedHeadersOptions

1 participant