mirror of
https://github.com/netbirdio/netbird.git
synced 2026-07-21 16:01:28 +02:00
The WS listener unconditionally trusted X-Real-Ip/X-Real-Port headers, letting any client forge the source address the relay logs. Gate header trust behind a trusted-proxy allowlist; ignore the headers unless the immediate peer matches a configured prefix. Defaults to never trusting the headers when the allowlist is empty. ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6833"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787141580&installation_id=146802194&pr_number=6833&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6833&signature=9cf182cc7be248e457dfdb56e8a047401276d8cc567ed8ae715ec1cc809f1b6a"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>/codesmith</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added `--trusted-proxies` to configure a comma-separated allowlist of trusted upstream proxy IPs/CIDRs. * **Behavior Changes** * Relay WebSocket now uses `X-Real-Ip` / `X-Real-Port` only when the immediate peer is from the configured trusted set; otherwise it falls back to the direct remote address. * Proxy client IP resolution is now consistent and honors `X-Forwarded-For` only through trusted hops. * **Operational** * Invalid `--trusted-proxies` values fail fast on startup. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
109 lines
3.1 KiB
Go
109 lines
3.1 KiB
Go
package proxy
|
|
|
|
import (
|
|
"net"
|
|
"net/netip"
|
|
"testing"
|
|
"time"
|
|
|
|
proxyproto "github.com/pires/go-proxyproto"
|
|
log "github.com/sirupsen/logrus"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
|
|
"github.com/netbirdio/netbird/trustedproxy"
|
|
)
|
|
|
|
func TestWrapProxyProtocol_OverridesRemoteAddr(t *testing.T) {
|
|
srv := &Server{
|
|
Logger: log.StandardLogger(),
|
|
TrustedProxies: trustedproxy.FromPrefixes([]netip.Prefix{netip.MustParsePrefix("127.0.0.1/32")}),
|
|
ProxyProtocol: true,
|
|
}
|
|
|
|
raw, err := net.Listen("tcp", "127.0.0.1:0")
|
|
require.NoError(t, err)
|
|
defer raw.Close()
|
|
|
|
ln := srv.wrapProxyProtocol(raw)
|
|
|
|
realClientIP := "203.0.113.50"
|
|
realClientPort := uint16(54321)
|
|
|
|
accepted := make(chan net.Conn, 1)
|
|
go func() {
|
|
conn, err := ln.Accept()
|
|
if err != nil {
|
|
return
|
|
}
|
|
accepted <- conn
|
|
}()
|
|
|
|
// Connect and send a PROXY v2 header.
|
|
conn, err := net.Dial("tcp", ln.Addr().String())
|
|
require.NoError(t, err)
|
|
defer conn.Close()
|
|
|
|
header := &proxyproto.Header{
|
|
Version: 2,
|
|
Command: proxyproto.PROXY,
|
|
TransportProtocol: proxyproto.TCPv4,
|
|
SourceAddr: &net.TCPAddr{IP: net.ParseIP(realClientIP), Port: int(realClientPort)},
|
|
DestinationAddr: &net.TCPAddr{IP: net.ParseIP("10.0.0.1"), Port: 443},
|
|
}
|
|
_, err = header.WriteTo(conn)
|
|
require.NoError(t, err)
|
|
|
|
select {
|
|
case accepted := <-accepted:
|
|
defer accepted.Close()
|
|
host, _, err := net.SplitHostPort(accepted.RemoteAddr().String())
|
|
require.NoError(t, err)
|
|
assert.Equal(t, realClientIP, host, "RemoteAddr should reflect the PROXY header source IP")
|
|
case <-time.After(2 * time.Second):
|
|
t.Fatal("timed out waiting for connection")
|
|
}
|
|
}
|
|
|
|
func TestProxyProtocolPolicy_TrustedRequires(t *testing.T) {
|
|
srv := &Server{
|
|
Logger: log.StandardLogger(),
|
|
TrustedProxies: trustedproxy.FromPrefixes([]netip.Prefix{netip.MustParsePrefix("10.0.0.0/8")}),
|
|
}
|
|
|
|
opts := proxyproto.ConnPolicyOptions{
|
|
Upstream: &net.TCPAddr{IP: net.ParseIP("10.0.0.1"), Port: 1234},
|
|
}
|
|
policy, err := srv.proxyProtocolPolicy(opts)
|
|
require.NoError(t, err)
|
|
assert.Equal(t, proxyproto.REQUIRE, policy, "trusted source should require PROXY header")
|
|
}
|
|
|
|
func TestProxyProtocolPolicy_UntrustedIgnores(t *testing.T) {
|
|
srv := &Server{
|
|
Logger: log.StandardLogger(),
|
|
TrustedProxies: trustedproxy.FromPrefixes([]netip.Prefix{netip.MustParsePrefix("10.0.0.0/8")}),
|
|
}
|
|
|
|
opts := proxyproto.ConnPolicyOptions{
|
|
Upstream: &net.TCPAddr{IP: net.ParseIP("203.0.113.50"), Port: 1234},
|
|
}
|
|
policy, err := srv.proxyProtocolPolicy(opts)
|
|
require.NoError(t, err)
|
|
assert.Equal(t, proxyproto.IGNORE, policy, "untrusted source should have PROXY header ignored")
|
|
}
|
|
|
|
func TestProxyProtocolPolicy_InvalidIPRejects(t *testing.T) {
|
|
srv := &Server{
|
|
Logger: log.StandardLogger(),
|
|
TrustedProxies: trustedproxy.FromPrefixes([]netip.Prefix{netip.MustParsePrefix("10.0.0.0/8")}),
|
|
}
|
|
|
|
opts := proxyproto.ConnPolicyOptions{
|
|
Upstream: &net.UnixAddr{Name: "/tmp/test.sock", Net: "unix"},
|
|
}
|
|
policy, err := srv.proxyProtocolPolicy(opts)
|
|
require.NoError(t, err)
|
|
assert.Equal(t, proxyproto.REJECT, policy, "unparsable address should be rejected")
|
|
}
|