Преглед изворни кода

Update documentation of TRUSTED_PROXY syntax and document limitations. (#9283)

* Update documentation of TRUSTED_PROXY syntax and document limitations.

Single IPs are now supported as of #9301.
Document the existing limitation of domain names, see #9210.

For IPs without `/`, I manually tested the behavior and found requests got rejected on my server before #9301. After #9301 is merged, I've tested again and found that requests are now authorized as expected. So I've updated the corresponding documentation to say "_IPs or_ ranges" where applicable.

Domain names are still silently ignored as of writing. I looked at the code, as described in #9210 investigation steps, and concluded that they are WAI (working as _implemented_ , not sure if _intended_ ). I don't particularly like the existing behavior (failures with no debuggable warnings or logs) but I try to document it as-is without judgement.

* Update TRUSTED_PROXY comments accordingly for Docker usage.

Single IPs are now supported as of #9301.
Document the existing limitation of domain names, see #9210.
Yuchen Shi пре 14 часа
родитељ
комит
818b57a9a9
2 измењених фајлова са 6 додато и 7 уклоњено
  1. 2 2
      Docker/README.md
  2. 4 5
      docs/en/admins/09_AccessControl.md

+ 2 - 2
Docker/README.md

@@ -351,8 +351,8 @@ services:
       #INTERNAL_HOST_ALLOWLIST: rss-bridge:80 rsshub:1200
 
       # Optional parameter, remove for automatic settings, set to 0 to disable,
-      # or (if you use a proxy) to a space-separated list of trusted IP ranges
-      # compatible with https://httpd.apache.org/docs/current/mod/mod_remoteip.html#remoteipinternalproxy
+      # or (if you use a proxy) to a space-separated list of trusted IPs or CIDR
+      # notation for ranges. Domain names are not supported and will be ignored.
       # This impacts which IP address is logged (X-Forwarded-For or REMOTE_ADDR).
       # This also impacts external authentication methods;
       # see https://freshrss.github.io/FreshRSS/en/admins/09_AccessControl.html

+ 4 - 5
docs/en/admins/09_AccessControl.md

@@ -58,13 +58,12 @@ variable containing the email address of the authenticated user (e.g. `REMOTE_US
 
 You may also use the `Remote-User` or `X-WebAuth-User` HTTP headers to integrate with a reverse-proxy’s authentication.
 
-To enable this feature, you need to add the IP range (in CIDR notation) of your trusted proxy in the `trusted_sources` configuration option.
-To allow only one IPv4, you can use a `/32` like this: `trusted_sources => [ '192.168.1.10/32' ]`.
-Likewise to allow only one IPv6, you can use a `/128` like this: `trusted_sources => [ '::1/128' ]`.
+To enable this feature, you need to add the IPs (or ranges in CIDR notation) of your trusted proxy in the `trusted_sources` configuration option.
 
-You may alternatively pass a `TRUSTED_PROXY` environment variable in a format compatible with [Apache’s `mod_remoteip` `RemoteIPInternalProxy`](https://httpd.apache.org/docs/current/mod/mod_remoteip.html#remoteipinternalproxy).
+You may alternatively pass a `TRUSTED_PROXY` environment variable, which is a space-separated list of IPs or CIDR notations like this: `192.168.1.10 ::1/128`.
+The format is largely compatible with [Apache’s `mod_remoteip` `RemoteIPInternalProxy`](https://httpd.apache.org/docs/current/mod/mod_remoteip.html#remoteipinternalproxy), except that domain names are not supported and will be silently ignored.
 
-> ☠️ WARNING: FreshRSS will trust any IP configured in the `trusted_sources` option, if your proxy isn’t properly secured, an attacker could simply attach this header and get admin access.
+> ☠️ WARNING: FreshRSS will trust any IP configured in the `trusted_sources` option and/or the `TRUSTED_PROXY` environment variable. If your proxy isn’t properly secured, an attacker could simply attach this header and get admin access.
 
 ### Authentik Proxy Provider