summaryrefslogtreecommitdiff
path: root/plugins/acl/localization
diff options
context:
space:
mode:
authorFelix Eckhofer <felix@eckhofer.com>2014-03-26 14:13:40 +0100
committerThomas Bruederli <thomas@roundcube.net>2014-04-25 18:40:53 +0200
commitf58a294949547ed132bf3cdb5815b68c659b992a (patch)
tree2285e1abf79f45dc7bbc0222651363f4eaf50165 /plugins/acl/localization
parentd71a711ab06483e62b1a7343e296ef8639352689 (diff)
Add config variable 'proxy_whitelist'
HTTP headers X_FORWARDED_* and X_REAL_IP are only evaluated when received from an IP listed in proxy_whitelist. Furthermore, only the last non-trusted IP from X-Forwarded-For is used in place of the real ip. Without this, an attacker can easily spoof the headers and control the result of the ip or ssl check. This fixes several problems with [3a4c9f42], [4d480b36] and [a520f331] as mentioned in #1489729. Conflicts: CHANGELOG
Diffstat (limited to 'plugins/acl/localization')
0 files changed, 0 insertions, 0 deletions