Re: [PR] fix(wolf-rbac): use trusted client IP source for access_check [apisix]

2026-05-11 Thread via GitHub


shreemaan-abhishek merged PR #13329:
URL: https://github.com/apache/apisix/pull/13329


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



[PR] fix(wolf-rbac): use trusted client IP source for access_check [apisix]

2026-05-05 Thread via GitHub


shreemaan-abhishek opened a new pull request, #13329:
URL: https://github.com/apache/apisix/pull/13329

   ### Description
   
   The wolf-rbac plugin populates the `clientIP` parameter sent to 
wolf-server's `/wolf/rbac/access_check` endpoint by reading 
`ctx.var.http_x_real_ip`, the **raw** `X-Real-IP` request header. This bypasses 
nginx's `real_ip` module: even though APISIX configures `real_ip_from = { 
"127.0.0.1", "unix:" }` by default — meaning nginx correctly rejects 
`X-Real-IP` from untrusted sources when computing `$remote_addr` — the plugin 
reads the original header directly, so any external client can supply an 
arbitrary `clientIP` value.
   
   This change replaces the raw-header read with 
`core.request.get_remote_client_ip(ctx)`, which returns `$remote_addr` after 
`real_ip` processing. The new behavior is:
   
   - Behind a trusted proxy (listed in `real_ip_from`): forwards the real 
client IP from the trusted header — same behavior the previous code intended.
   - From untrusted sources: forwards the actual TCP peer address; the spoofed 
header is ignored, matching nginx's standard handling.
   
    Which issue(s) this PR fixes:
   
   Fixes #
   
   ### Checklist
   
   - [x] I have explained the need for this PR and the problem it solves
   - [x] I have explained the changes or the new features added to this PR
   - [ ] I have added tests corresponding to this change
   - [ ] I have updated the documentation to reflect this change
   - [ ] I have verified that this change is backward compatible (If not, 
please discuss on the [APISIX mailing 
list](https://github.com/apache/apisix/tree/master#community) first)
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]