mirror of
https://codeberg.org/icewind/real-ip.git
synced 2026-10-01 09:04:12 +02:00
don't return any forwarded hops if the header is invalid
This commit is contained in:
parent
c9aea2fc74
commit
fcd6646f1b
2 changed files with 54 additions and 16 deletions
23
src/lib.rs
23
src/lib.rs
|
|
@ -74,6 +74,7 @@ pub fn real_ip(headers: &HeaderMap, remote: IpAddr, trusted_proxies: &[IpNet]) -
|
|||
|
||||
'outer: for hop in hops.rev() {
|
||||
for proxy in trusted_proxies {
|
||||
dbg!(proxy);
|
||||
if proxy.contains(&hop) {
|
||||
continue 'outer;
|
||||
}
|
||||
|
|
@ -110,3 +111,25 @@ pub fn get_forwarded_for(headers: &HeaderMap) -> impl DoubleEndedIterator<Item =
|
|||
#[allow(dead_code)]
|
||||
#[doc = include_str!("../README.md")]
|
||||
fn test_readme_examples() {}
|
||||
|
||||
#[test]
|
||||
fn test_malformed() {
|
||||
use http::header::HeaderValue;
|
||||
let mut headers = HeaderMap::new();
|
||||
headers.insert(
|
||||
"forwarded",
|
||||
HeaderValue::from_static(
|
||||
"by=203.0.111.42;for=1.2.3.4:8888,for=5.6.7.8;proto=https;nonsense",
|
||||
),
|
||||
);
|
||||
let trusted_proxies = [
|
||||
IpAddr::from([2, 3, 4, 5]).into(),
|
||||
IpAddr::from([5, 6, 7, 8]).into(),
|
||||
];
|
||||
let remote = IpAddr::from([2, 3, 4, 5]);
|
||||
assert!(get_forwarded_for(&headers).next().is_none());
|
||||
assert_eq!(
|
||||
Some(IpAddr::from([2, 3, 4, 5])),
|
||||
real_ip(&headers, remote, &trusted_proxies)
|
||||
);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue