Correctly calculate base URL when behind multiple reverse proxies

Signed-off-by: Nathan Rennie-Waldock <nathan.renniewaldock@gmail.com>
This commit is contained in:
Nathan Rennie-Waldock
2017-05-01 17:44:10 +01:00
parent 154d4316e6
commit 3b3491384a
@@ -60,8 +60,21 @@ public class NetworkService {
private static URI calculateProxyUri(HttpServletRequest request) throws URISyntaxException { private static URI calculateProxyUri(HttpServletRequest request) throws URISyntaxException {
String xForardedHost = request.getHeader(X_FORWARDED_HOST); String xForardedHost = request.getHeader(X_FORWARDED_HOST);
// If the request has been through multiple reverse proxies,
// We need to return the original Host that the client used
if (xForardedHost != null) {
xForardedHost = xForardedHost.split(",")[0];
}
if(!isValidXForwardedHost(xForardedHost)) { if(!isValidXForwardedHost(xForardedHost)) {
xForardedHost = request.getHeader(X_FORWARDED_SERVER); xForardedHost = request.getHeader(X_FORWARDED_SERVER);
// If the request has been through multiple reverse proxies,
// We need to return the original Host that the client used
if (xForardedHost != null) {
xForardedHost = xForardedHost.split(",")[0];
}
if(!isValidXForwardedHost(xForardedHost)) { if(!isValidXForwardedHost(xForardedHost)) {
throw new RuntimeException("Cannot calculate proxy uri without HTTP header " + X_FORWARDED_HOST); throw new RuntimeException("Cannot calculate proxy uri without HTTP header " + X_FORWARDED_HOST);
} }