Commit bd6f427d authored by Dom Sekotill's avatar Dom Sekotill
Browse files

Trust private IP ranges for X-Forwarded-For headers

parent a9381087
Loading
Loading
Loading
Loading
+4 −0
Original line number Diff line number Diff line
@@ -13,7 +13,11 @@ server {
	server_name _;
	root /app/static;

	# Consider all private IP addresses safe sources for X-Forwarded-For
	set_real_ip_from 10.0.0.0/8;
	set_real_ip_from 172.16.0.0/12;
	set_real_ip_from 192.168.0.0/16;
	set_real_ip_from fd00::/8;
	real_ip_header X-Forwarded-For;

	location ~ \.php$ {