🔒 fix: Prevent X-Forwarded-For IP spoofing in Rate Limiter - #54
Conversation
Update RateLimitFilter to securely parse the proxy chain and ensure only trusted internal IPs can spoof X-Forwarded-For headers. Added comprehensive tests to verify fix. Co-authored-by: Sanan507 <227714367+Sanan507@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Update RateLimitFilter to securely parse the proxy chain and ensure only trusted internal IPs can spoof X-Forwarded-For headers. Added comprehensive tests to verify fix. Co-authored-by: Sanan507 <227714367+Sanan507@users.noreply.github.com>
Update RateLimitFilter to securely parse the proxy chain and ensure only trusted internal IPs can spoof X-Forwarded-For headers. Added comprehensive tests to verify fix. Co-authored-by: Sanan507 <227714367+Sanan507@users.noreply.github.com>
🎯 What: The
⚠️ Risk: An attacker could trivially bypass rate limiting by rotating a spoofed
RateLimitFilterpreviously trusted theX-Forwarded-Forheader blindly, allowing clients to spoof their IP address. This PR fixes the vulnerability by validating that the connection comes from an internal network (e.g. proxy) before trusting the header, and correctly parsing proxy chains right-to-left.X-Forwarded-Forheader, allowing a DoS attack against computationally expensive endpoints (like/api/simulations).🛡️ Solution: The
resolveClientIpmethod now checks ifrequest.getRemoteAddr()is a private/internal IP. If it is, it parses theX-Forwarded-Forlist from right to left to pick the first non-internal IP, ensuring we grab the real client IP appended by our trusted proxy and ignore any spoofed values. Tests were added to guarantee this behavior.PR created automatically by Jules for task 9241149742628663330 started by @Sanan507