Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
046b17b
fix(web): honor X-Forwarded-* so the real client IP reaches the pipeline
marcelo-maciel Jul 11, 2026
f537e91
Merge branch 'main' into fix/web-forwarded-headers
marcelo-maciel Jul 13, 2026
75475d3
fix(web): bind forwarded-headers trust to configured proxies
marcelo-maciel Jul 13, 2026
85aa03b
fix(web): name the offending setting when trusted-proxy config is mal…
marcelo-maciel Aug 14, 2026
171abea
Merge branch 'main' into fix/web-forwarded-headers
marcelo-maciel Aug 14, 2026
e7dbe6b
build: pin SSH.NET to 2026.0.0 so restore passes while #1333 is open
marcelo-maciel Aug 17, 2026
5def7d9
fix(web): reject a trusted-proxy ForwardLimit below 1 at startup
marcelo-maciel Aug 17, 2026
cb62b10
docs(web): record why X-Forwarded-Host stays out of the flag list
marcelo-maciel Aug 17, 2026
8e0d7de
build(deps): bump Testcontainers to 4.14.0 and SourceLink past their …
marcelo-maciel Sep 14, 2026
6816b7d
fix(infra): pull MinIO from quay.io on a pinned tag, not Docker Hub
marcelo-maciel Sep 14, 2026
6f0b8f8
fix(web): rebuild the forwarded-headers trust list instead of appendi…
marcelo-maciel Sep 17, 2026
e1ab57b
fix(infra): pull minio/mc from quay.io too, not just minio/minio
marcelo-maciel Sep 18, 2026
99e5514
build(deps): drop the dead SSH.NET pin
marcelo-maciel Sep 18, 2026
71000c3
docs(web): say what a ForwardLimit above the real hop count costs
marcelo-maciel Sep 18, 2026
00ec8e8
test(security): read the session this request created, not the newest…
marcelo-maciel Sep 18, 2026
f568551
Merge remote-tracking branch 'origin/main' into pr/1386
iammukeshm Sep 25, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions src/BuildingBlocks/Web/Extensions.cs
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,16 @@ public static IHostApplicationBuilder AddHeroPlatform(this IHostApplicationBuild
.GetSection(nameof(TrustedProxyOptions)).Get<TrustedProxyOptions>() ?? new TrustedProxyOptions();
builder.Services.Configure<ForwardedHeadersOptions>(forwarded =>
{
// A hop count below 1 is never what an operator means, and neither bad value announces itself:
// 0 truncates the unwind loop to zero iterations, so forwarded headers stop being processed with
// no error, while a negative value overflows the middleware's buffer allocation and 500s every
// request - including requests carrying no forwarded headers at all. Fail the boot instead.
if (trustedProxy.ForwardLimit < 1)
{
throw new InvalidOperationException(
$"{nameof(TrustedProxyOptions)}:{nameof(TrustedProxyOptions.ForwardLimit)} is {trustedProxy.ForwardLimit}, which is not a valid proxy hop count: it must be at least 1 (one hop per proxy in front of the app).");
}

forwarded.ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto;
forwarded.ForwardLimit = trustedProxy.ForwardLimit;

Expand Down
17 changes: 17 additions & 0 deletions src/BuildingBlocks/Web/TrustedProxy/TrustedProxyOptions.cs
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,13 @@ namespace FSH.Framework.Web.TrustedProxy;
/// outside the proxy network cannot forge its own IP/scheme. When no proxies or networks are
/// configured, the framework default (loopback only) stands and forwarded headers from any other
/// source are ignored.
/// <para>
/// Only X-Forwarded-For and X-Forwarded-Proto are honoured. X-Forwarded-Host is deliberately left
/// out: rewriting Request.Host from a header is a host-header injection primitive, and the endpoints
/// that build a public URL from the request (user registration and confirmation e-mails) would then
/// send links pointing wherever the header said. The trade-off is that Request.Host keeps the
/// internal host behind a proxy, and those links carry it.
/// </para>
/// </summary>
public sealed class TrustedProxyOptions
{
Expand All @@ -20,6 +27,16 @@ public sealed class TrustedProxyOptions
/// Number of proxy hops to unwind from X-Forwarded-For. Must match the real ingress hop count
/// (cloudflared → Caddy → app is 2). The framework default of 1 reads only the rightmost hop,
/// which yields the nearest proxy's IP (or an attacker-injected value) in a multi-hop topology.
/// Must be at least 1: anything lower is rejected at startup, since 0 would silently stop
/// forwarded-header processing and a negative value would fail every request.
/// <para>
/// Setting it higher than the real hop count is what turns this into a vulnerability: the
/// middleware trusts one entry per hop, counting from the right, and only the peer itself is
/// checked against the trust list. A limit of 2 with a single proxy in front means the value the
/// proxy appended is discarded in favour of the one the client sent, so the caller picks its own
/// RemoteIpAddress and every IP-based rate limit and audit entry follows it. Count the proxies
/// that actually rewrite the header, not the ones in the diagram.
/// </para>
/// </summary>
public int ForwardLimit { get; init; } = 1;
}
16 changes: 16 additions & 0 deletions src/Tests/Framework.Tests/Web/TrustedProxyOptionsBindingTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -93,5 +93,21 @@ public void ForwardedHeaders_Should_NameTheSetting_When_KnownNetworkMalformed()
exception.Message.ShouldContain("10.0.0.0/999");
}

[Theory]
[InlineData("-1")] // negative — overflows the middleware's buffer allocation, 500s every request
[InlineData("0")] // zero — truncates the unwind loop, forwarded headers silently stop being read
public void ForwardedHeaders_Should_NameTheSetting_When_ForwardLimitBelowOne(string forwardLimit)
{
// Act - no proxies or networks configured, so this has to be rejected before the trust-boundary block.
var exception = Should.Throw<InvalidOperationException>(() => Resolve(new Dictionary<string, string?>
{
[$"{nameof(TrustedProxyOptions)}:{nameof(TrustedProxyOptions.ForwardLimit)}"] = forwardLimit,
}));

// Assert
exception.Message.ShouldContain("TrustedProxyOptions:ForwardLimit");
exception.Message.ShouldContain($"is {forwardLimit}");
}

#endregion
}
Loading