mirror of
https://github.com/KubaPro010/fm-dx-webserver.git
synced 2026-07-31 17:29:19 +02:00
localhost
This commit is contained in:
+20
-5
@@ -343,17 +343,32 @@ function findServerFiles(plugins) {
|
|||||||
return results;
|
return results;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function normalizeIp(ip) {
|
||||||
|
if(ip && ip.startsWith('::ffff:')) return ip.substring(7);
|
||||||
|
return ip;
|
||||||
|
}
|
||||||
|
|
||||||
|
function isLocalhost(ip) {
|
||||||
|
const normalized = normalizeIp(ip);
|
||||||
|
return normalized === '127.0.0.1' || normalized === '::1';
|
||||||
|
}
|
||||||
|
|
||||||
|
function isTrustedProxy(ip) {
|
||||||
|
return serverConfig.trustedProxies.includes(normalizeIp(ip));
|
||||||
|
}
|
||||||
|
|
||||||
function getIpAddress(request) {
|
function getIpAddress(request) {
|
||||||
const remoteIp = request.socket.remoteAddress;
|
const remoteIpRaw = request.socket.remoteAddress;
|
||||||
|
const remoteIp = normalizeIp(remoteIpRaw);
|
||||||
const xff = request.headers['x-forwarded-for'];
|
const xff = request.headers['x-forwarded-for'];
|
||||||
|
|
||||||
// If X-Forwarded-For is present but request is NOT from a trusted proxy → suspicious
|
if (xff && !isLocalhost(remoteIp) && !isTrustedProxy(remoteIp)) {
|
||||||
if (xff && !serverConfig.trustedProxies.includes(remoteIp)) {
|
consoleCmd.logSecurity(`Untrusted proxy tried to set X-Forwarded-For: ${xff} (remote: ${remoteIpRaw})`);
|
||||||
consoleCmd.logSecurity(`Untrusted proxy tried to set X-Forwarded-For: ${xff} (remote: ${remoteIp})`);
|
|
||||||
return remoteIp;
|
return remoteIp;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (xff && serverConfig.trustedProxies.includes(remoteIp)) return xff.split(',')[0].trim();
|
if (xff) return normalizeIp(xff.split(',')[0].trim());
|
||||||
|
|
||||||
return remoteIp;
|
return remoteIp;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user