envoyproxy / envoyproxy/gateway

Support for Forwarded header RFC7239

Open
#2,288 2 comments 4 reactions 0 assignees View on GitHub
kind/enhancement stale
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

*Description*:
Having support for the Forwarded header would be really useful. The issue with relying on X-Forwarded-For is that those can be forged easily. The `Forwarded` header supports adding a secret key so that downstream sources can validate that the header actually coming from your proxy.

If there was a way to restrict the existing X-Forwarded-* headers so they only applied to certain IP ranges that would be great. If we could have a built-in option to dynamically load IP ranges from CloudFlare upon start (with a refresh once a week) that would be a really fantastic solution.

[optional *Relevant Links*:]
https://datatracker.ietf.org/doc/html/rfc7239
https://developers.cloudflare.com/support/troubleshooting/restoring-visitor-ips/restoring-original-visitor-ips/
https://www.cloudflare.com/ips/

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.