TsgcWebSocketFirewall › Methods › IsForwardedIPAllowed

IsForwardedIPAllowed Method

Per-request verdict for an address resolved from the forwarded headers. Applies the address-identity checks and deliberately leaves out the connection-scoped ones.

Syntax

function IsForwardedIPAllowed(const aIP: string): Boolean;

Parameters

NameTypeDescription
aIPconst stringClient address returned by ResolveClientIP. Both IPv4 and IPv6 are supported.

Return Value

True when the address passes every applicable check; False when whitelist, blacklist, bans, GeoIP or a custom rule rejects it. On rejection OnFiltered and OnViolation fire with the matching violation type. (Boolean)

Remarks

IsForwardedIPAllowed runs the same address-identity checks as IsConnectionAllowed, that is Whitelist, Blacklist, active bans, GeoIP and CustomRules, but it skips the connection-scoped ones. RateLimit.MaxConnectionsPerIP and the internal connection counter are excluded on purpose, because they track sockets and a reverse proxy carries requests from many end clients over a small number of upstream connections. Calling it once per request is therefore safe and does not inflate any counter. The servers invoke it automatically after ResolveClientIP produces an address different from the peer, answering a rejected request with 403 Forbidden on the HTTP servers and dropping the connection for WebSocket and the other protocol handlers, so a manual call is only needed in custom request pipelines. The method is thread-safe. See Firewall: Real Client IP Behind a Reverse Proxy.

Example


vClientIP := sgcWebSocketFirewall1.ResolveClientIP(Connection.PeerIP,
  Connection.HeadersRequest);
if not sgcWebSocketFirewall1.IsForwardedIPAllowed(vClientIP) then
  Connection.Disconnect;

Back to Methods