mirror of
https://github.com/Nezumi-2711/9router.git
synced 2026-09-22 13:38:31 +00:00
fix(security): don't trust loopback socket as local when request arrives via reverse proxy
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -11,9 +11,14 @@ http.createServer = (...args) => {
|
|||||||
if (!handler) return origCreate(...args);
|
if (!handler) return origCreate(...args);
|
||||||
const wrapped = (req, res) => {
|
const wrapped = (req, res) => {
|
||||||
const ip = req.socket && req.socket.remoteAddress ? req.socket.remoteAddress : "";
|
const ip = req.socket && req.socket.remoteAddress ? req.socket.remoteAddress : "";
|
||||||
|
// Forwarding headers present = request arrived via a reverse proxy; loopback
|
||||||
|
// socket is the proxy hop, not the end-user, so it must not be trusted as local.
|
||||||
|
const viaProxy = !!(req.headers["x-forwarded-for"] || req.headers["x-real-ip"]);
|
||||||
delete req.headers["x-9r-real-ip"];
|
delete req.headers["x-9r-real-ip"];
|
||||||
delete req.headers["x-forwarded-for"];
|
delete req.headers["x-forwarded-for"];
|
||||||
|
delete req.headers["x-9r-via-proxy"];
|
||||||
req.headers["x-9r-real-ip"] = ip;
|
req.headers["x-9r-real-ip"] = ip;
|
||||||
|
if (viaProxy) req.headers["x-9r-via-proxy"] = "1";
|
||||||
return handler(req, res);
|
return handler(req, res);
|
||||||
};
|
};
|
||||||
return origCreate(...rest, wrapped);
|
return origCreate(...rest, wrapped);
|
||||||
|
|||||||
@@ -90,6 +90,9 @@ function isLoopbackHostname(h) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export function isLocalRequest(request) {
|
export function isLocalRequest(request) {
|
||||||
|
// Stamped by custom-server.js when forwarding headers exist: request came through
|
||||||
|
// a reverse proxy, so the loopback socket is the proxy hop, not the end-user.
|
||||||
|
if (request.headers.get("x-9r-via-proxy")) return false;
|
||||||
// Trusted peer IP from TCP socket (custom-server.js); unspoofable. Primary anchor for "local".
|
// Trusted peer IP from TCP socket (custom-server.js); unspoofable. Primary anchor for "local".
|
||||||
const realIp = request.headers.get("x-9r-real-ip");
|
const realIp = request.headers.get("x-9r-real-ip");
|
||||||
if (realIp) {
|
if (realIp) {
|
||||||
|
|||||||
Reference in New Issue
Block a user