[MM-15639] Add config setting to explicitly define which IP headers are trusted (#10907)

* Add config setting to explicitly define which IP headers are trusted

* fix variable shadowing

* Optimize code flow; Add Ratelimit test for header set

* Extend Ratelimit tests

* Add additional unit tests

* Structured logging
Этот коммит содержится в:
Daniel Schalla
2019-05-24 20:22:13 +02:00
коммит произвёл GitHub
родитель e8af4872c6
Коммит 2d97f01781
11 изменённых файлов: 113 добавлений и 30 удалений

Просмотреть файл

@@ -4,7 +4,6 @@
package app
import (
"fmt"
"html/template"
"net/http"
"strconv"
@@ -134,7 +133,8 @@ func (a *App) HTMLTemplates() *template.Template {
}
func (a *App) Handle404(w http.ResponseWriter, r *http.Request) {
mlog.Debug(fmt.Sprintf("%v: code=404 ip=%v", r.URL.Path, utils.GetIpAddress(r)))
ipAddress := utils.GetIpAddress(r, a.Config().ServiceSettings.TrustedProxyIPHeader)
mlog.Debug("not found handler triggered", mlog.String("path", r.URL.Path), mlog.Int("code", 404), mlog.String("ip", ipAddress))
if *a.Config().ServiceSettings.WebserverMode == "disabled" {
http.NotFound(w, r)