GUACAMOLE-47: Remove XFF header code due to security concerns.

This commit is contained in:
Nick Couchman
2017-01-28 12:58:53 -05:00
parent 00df0d75eb
commit 3fadac632c

View File

@@ -68,17 +68,14 @@ public class APIRequest extends HttpServletRequestWrapper {
super(request);
// Try a few methods to get client info.
if (request.getHeader("X-Forwarded-For") != null && !request.getHeader("X-Forwarded-For").isEmpty())
this.remoteHost = null;
else if (request.getRemoteHost() != null && !request.getRemoteHost().isEmpty())
// Grab the remote host info.
if (request.getRemoteHost() != null && !request.getRemoteHost().isEmpty())
this.remoteHost = request.getRemoteHost();
else
this.remoteHost = null;
if(request.getHeader("X-Forwarded-For") != null && !request.getHeader("X-Forwarded-For").isEmpty())
this.remoteAddr = request.getHeader("X-Forwarded-For");
else if(request.getRemoteHost() != null && !request.getRemoteAddr().isEmpty())
// Grab the remote ip info.
if(request.getRemoteHost() != null && !request.getRemoteAddr().isEmpty())
this.remoteAddr = request.getRemoteAddr();
else
this.remoteAddr = null;