mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 10:27:08 +02:00
The RealIP middleware rewrote RemoteAddr from the True-Client-IP, X-Real-IP and X-Forwarded-For headers on every request, including when no trusted reverse proxy was configured. The login rate limiters on /auth/login and the Jellyfin /Users/AuthenticateByName derived their bucket from that value, so an unauthenticated client could rotate a forwarding header and get a fresh bucket for every password attempt, defeating the brute-force protection. Resolve the client IP with chi's ClientIPFrom* middlewares instead. The forwarding headers are only honoured when ExtAuth.TrustedSources is set and the connecting peer is in that list, reusing the trust check that external authentication already applies; otherwise the peer address is used. The X-Forwarded-For chain is now walked against the trusted CIDRs rather than taking its leftmost entry, so a spoofed value prepended by the client is skipped. Both limiters now key on the resolved address. The resolved address is still mirrored into RemoteAddr, so request logging, player registration and the Jellyfin local-network check keep reporting the client rather than the proxy. Reported by gehan-psbc. |
||
|---|---|---|
| .. | ||
| backgrounds | ||
| events | ||
| filter | ||
| imghttp | ||
| jellyfin | ||
| nativeapi | ||
| public | ||
| subsonic | ||
| testdata | ||
| auth.go | ||
| auth_test.go | ||
| initial_setup.go | ||
| initial_setup_test.go | ||
| middlewares.go | ||
| middlewares_test.go | ||
| serve_index.go | ||
| serve_index_test.go | ||
| server.go | ||
| server_suite_test.go | ||
| server_test.go | ||
| throttle_backlog.go | ||
| throttle_backlog_test.go | ||