fix: Forward real client IP through Docker proxy

- Update setupProxy.js to forward X-Real-IP and X-Forwarded-For headers
- Improve IP detection in backend middleware to prioritize X-Real-IP
- Add debug logging for IP detection in development mode
- Update .env.example with clearer IP configuration examples
- Enable debug logging in docker-compose.dev.yml

This fixes the issue where Docker network IPs (172.20.x.x) were being
detected instead of the real client IP addresses.

To fix IP restrictions, update your .env file:
ALLOWED_IPS=10.30.30.0/24,<your-other-ips>

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2025-07-23 15:03:24 +02:00
parent 10605c6739
commit 77bed5122f
4 changed files with 35 additions and 5 deletions
+5 -1
View File
@@ -10,7 +10,11 @@ SESSION_TIMEOUT=1800
# IP Restrictions # IP Restrictions
ENABLE_IP_RESTRICTION=true ENABLE_IP_RESTRICTION=true
ALLOWED_IPS=192.168.1.0/24,10.0.0.5,172.16.0.0/16 # Add your IP or subnet here. Examples:
# - Single IP: 10.30.30.2
# - Subnet: 10.30.30.0/24
# - Multiple: 10.30.30.2,192.168.1.0/24,172.16.0.0/16
ALLOWED_IPS=10.30.30.0/24,192.168.1.0/24,172.16.0.0/16,127.0.0.1
# MinIO Configuration # MinIO Configuration
DEFAULT_MINIO_ALIAS=kopiaminio DEFAULT_MINIO_ALIAS=kopiaminio
+15 -4
View File
@@ -13,15 +13,26 @@ const ipFilterMiddleware = (req, res, next) => {
return next(); return next();
} }
// Get client IP // Get client IP - priority order for headers when behind proxy
const clientIp = req.ip || const clientIp = req.headers['x-real-ip'] ||
req.headers['x-forwarded-for']?.split(',')[0].trim() ||
req.ip ||
req.connection.remoteAddress || req.connection.remoteAddress ||
req.socket.remoteAddress || req.socket.remoteAddress;
req.headers['x-forwarded-for']?.split(',')[0];
// Normalize IPv6 localhost to IPv4 // Normalize IPv6 localhost to IPv4
const normalizedIp = clientIp === '::1' ? '127.0.0.1' : clientIp; const normalizedIp = clientIp === '::1' ? '127.0.0.1' : clientIp;
// Debug logging in development
if (config.app.env === 'development') {
logger.debug(`IP Filter Debug - Headers: ${JSON.stringify({
'x-real-ip': req.headers['x-real-ip'],
'x-forwarded-for': req.headers['x-forwarded-for'],
'req.ip': req.ip,
'detected': normalizedIp
})}`);
}
try { try {
// Check if IP is in allowed list // Check if IP is in allowed list
const isAllowed = ipRangeCheck(normalizedIp, config.security.allowedIps); const isAllowed = ipRangeCheck(normalizedIp, config.security.allowedIps);
+1
View File
@@ -16,6 +16,7 @@ services:
PORT: 7510 PORT: 7510
LOG_DIR: /app/logs LOG_DIR: /app/logs
TEMP_DIR: /app/temp TEMP_DIR: /app/temp
LOG_LEVEL: debug
env_file: env_file:
- .env - .env
ports: ports:
+14
View File
@@ -7,6 +7,20 @@ module.exports = function(app) {
target: process.env.BACKEND_URL || 'http://backend:7510', target: process.env.BACKEND_URL || 'http://backend:7510',
changeOrigin: true, changeOrigin: true,
logLevel: 'debug', logLevel: 'debug',
// Forward the real IP address
onProxyReq: (proxyReq, req, res) => {
// Get the real client IP
const clientIp = req.headers['x-forwarded-for'] ||
req.connection.remoteAddress ||
req.socket.remoteAddress ||
req.connection.socket.remoteAddress;
// Set the forwarded headers
proxyReq.setHeader('X-Forwarded-For', clientIp);
proxyReq.setHeader('X-Real-IP', clientIp);
proxyReq.setHeader('X-Forwarded-Proto', req.protocol);
proxyReq.setHeader('X-Forwarded-Host', req.headers.host);
},
onError: (err, req, res) => { onError: (err, req, res) => {
console.error('Proxy Error:', err); console.error('Proxy Error:', err);
res.status(500).json({ error: 'Proxy Error', message: err.message }); res.status(500).json({ error: 'Proxy Error', message: err.message });