From a6bb58717d3a1ae0fbe735f30d3e7baa1a2e7923 Mon Sep 17 00:00:00 2001 From: "Chinmay D. Pai" Date: Thu, 11 Jun 2020 18:30:00 +0530 Subject: [PATCH] fix: use remote_addr instead of user-defined header ip $proxy_add_x_forwarded_for sets the user defined ip in the request. changing it to $remote_addr ensures that nginx sets the remote ip itself, disregarding user-specified ip from the request. Signed-off-by: Chinmay D. Pai --- bench/config/templates/nginx.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bench/config/templates/nginx.conf b/bench/config/templates/nginx.conf index 9df365f3..06fc0b2b 100644 --- a/bench/config/templates/nginx.conf +++ b/bench/config/templates/nginx.conf @@ -85,7 +85,7 @@ server { } location @webserver { - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Frappe-Site-Name {{ site_name }}; proxy_set_header Host $host;