ghost: remove the client-written X-Forwarded-For chain on its router (R-753)
Express trust proxy true — leftmost XFF; its brute-force buckets are keyed by IP (+username). Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable. Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -34,6 +34,10 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.routers.ghost.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
- "traefik.http.routers.ghost.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
||||||
|
# R-753: this app reads the LEFTMOST X-Forwarded-For entry, which a stranger writes once traefik keeps the
|
||||||
|
# tunnel's chain — so its chain is removed here (it then reads traefik's X-Real-Ip or peer; never forgeable).
|
||||||
|
- "traefik.http.middlewares.ghost-xff.headers.customrequestheaders.X-Forwarded-For="
|
||||||
|
- "traefik.http.routers.ghost.middlewares=ghost-xff"
|
||||||
- "traefik.http.routers.ghost.entrypoints=websecure"
|
- "traefik.http.routers.ghost.entrypoints=websecure"
|
||||||
- "traefik.http.routers.ghost.tls=true"
|
- "traefik.http.routers.ghost.tls=true"
|
||||||
- "traefik.http.routers.ghost.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.ghost.tls.certresolver=letsencrypt"
|
||||||
|
|||||||
Reference in New Issue
Block a user