mirror of
https://github.com/netbirdio/netbird.git
synced 2026-07-21 16:01:28 +02:00
The WS listener unconditionally trusted X-Real-Ip/X-Real-Port headers, letting any client forge the source address the relay logs. Gate header trust behind a trusted-proxy allowlist; ignore the headers unless the immediate peer matches a configured prefix. Defaults to never trusting the headers when the allowlist is empty. ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6833"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787141580&installation_id=146802194&pr_number=6833&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6833&signature=9cf182cc7be248e457dfdb56e8a047401276d8cc567ed8ae715ec1cc809f1b6a"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>/codesmith</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added `--trusted-proxies` to configure a comma-separated allowlist of trusted upstream proxy IPs/CIDRs. * **Behavior Changes** * Relay WebSocket now uses `X-Real-Ip` / `X-Real-Port` only when the immediate peer is from the configured trusted set; otherwise it falls back to the direct remote address. * Proxy client IP resolution is now consistent and honors `X-Forwarded-For` only through trusted hops. * **Operational** * Invalid `--trusted-proxies` values fail fast on startup. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
133 lines
3.3 KiB
Go
133 lines
3.3 KiB
Go
package trustedproxy
|
|
|
|
import (
|
|
"fmt"
|
|
"net/netip"
|
|
"strings"
|
|
)
|
|
|
|
// List holds a parsed set of trusted upstream proxy prefixes and answers trust
|
|
// questions against it. The zero value (and a nil *List) is a valid, empty list
|
|
// that never trusts any address, so callers can use it without a nil check.
|
|
type List struct {
|
|
prefixes []netip.Prefix
|
|
}
|
|
|
|
// Parse parses a comma-separated list of CIDR prefixes or bare IPs into a List.
|
|
// Bare IPs are converted to single-host prefixes (/32 or /128). An empty input
|
|
// yields an empty List that trusts nothing.
|
|
func Parse(raw string) (*List, error) {
|
|
if raw == "" {
|
|
return &List{}, nil
|
|
}
|
|
|
|
parts := strings.Split(raw, ",")
|
|
prefixes := make([]netip.Prefix, 0, len(parts))
|
|
for _, part := range parts {
|
|
part = strings.TrimSpace(part)
|
|
if part == "" {
|
|
continue
|
|
}
|
|
|
|
prefix, err := netip.ParsePrefix(part)
|
|
if err == nil {
|
|
prefixes = append(prefixes, prefix)
|
|
continue
|
|
}
|
|
|
|
addr, addrErr := netip.ParseAddr(part)
|
|
if addrErr != nil {
|
|
return nil, fmt.Errorf("parse trusted proxy %q: not a valid CIDR or IP: %w", part, addrErr)
|
|
}
|
|
|
|
bits := 32
|
|
if addr.Is6() {
|
|
bits = 128
|
|
}
|
|
prefixes = append(prefixes, netip.PrefixFrom(addr, bits))
|
|
}
|
|
return &List{prefixes: prefixes}, nil
|
|
}
|
|
|
|
// FromPrefixes wraps an already-parsed set of prefixes in a List.
|
|
func FromPrefixes(prefixes []netip.Prefix) *List {
|
|
return &List{prefixes: prefixes}
|
|
}
|
|
|
|
// Empty reports whether the list contains no prefixes.
|
|
func (l *List) Empty() bool {
|
|
return l == nil || len(l.prefixes) == 0
|
|
}
|
|
|
|
// IsTrusted reports whether the given host:port or bare IP falls within the list.
|
|
func (l *List) IsTrusted(remoteAddr string) bool {
|
|
if l.Empty() {
|
|
return false
|
|
}
|
|
return l.Contains(ExtractHostIP(remoteAddr))
|
|
}
|
|
|
|
// Contains reports whether the given address falls within any trusted prefix.
|
|
func (l *List) Contains(addr netip.Addr) bool {
|
|
if l.Empty() || !addr.IsValid() {
|
|
return false
|
|
}
|
|
for _, prefix := range l.prefixes {
|
|
if prefix.Contains(addr) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
// ResolveClientIP extracts the real client IP from X-Forwarded-For using the
|
|
// list. It walks the XFF chain right-to-left, skipping IPs that match trusted
|
|
// prefixes; the first untrusted IP is the real client. If the list is empty or
|
|
// remoteAddr is not trusted, it returns the remoteAddr IP directly, ignoring any
|
|
// forwarding headers.
|
|
func (l *List) ResolveClientIP(remoteAddr, xff string) netip.Addr {
|
|
remoteIP := ExtractHostIP(remoteAddr)
|
|
|
|
if l.Empty() || !l.Contains(remoteIP) {
|
|
return remoteIP
|
|
}
|
|
|
|
if xff == "" {
|
|
return remoteIP
|
|
}
|
|
|
|
parts := strings.Split(xff, ",")
|
|
for i := len(parts) - 1; i >= 0; i-- {
|
|
ip := strings.TrimSpace(parts[i])
|
|
if ip == "" {
|
|
continue
|
|
}
|
|
addr, err := netip.ParseAddr(ip)
|
|
if err != nil {
|
|
continue
|
|
}
|
|
addr = addr.Unmap()
|
|
if !l.Contains(addr) {
|
|
return addr
|
|
}
|
|
}
|
|
|
|
if first := strings.TrimSpace(parts[0]); first != "" {
|
|
if addr, err := netip.ParseAddr(first); err == nil {
|
|
return addr.Unmap()
|
|
}
|
|
}
|
|
return remoteIP
|
|
}
|
|
|
|
// ExtractHostIP parses the IP from a host:port string and returns it unmapped.
|
|
func ExtractHostIP(hostPort string) netip.Addr {
|
|
if ap, err := netip.ParseAddrPort(hostPort); err == nil {
|
|
return ap.Addr().Unmap()
|
|
}
|
|
if addr, err := netip.ParseAddr(hostPort); err == nil {
|
|
return addr.Unmap()
|
|
}
|
|
return netip.Addr{}
|
|
}
|