TsgcWebSocketFirewall › Methods › IsForwardedIPAllowed
Per-request verdict for an address resolved from the forwarded headers. Applies the address-identity checks and deliberately leaves out the connection-scoped ones.
function IsForwardedIPAllowed(const aIP: string): Boolean;
| Name | Type | Description |
|---|---|---|
aIP | const string | Client address returned by ResolveClientIP. Both IPv4 and IPv6 are supported. |
True when the address passes every applicable check; False when whitelist, blacklist, bans, GeoIP or a custom rule rejects it. On rejection OnFiltered and OnViolation fire with the matching violation type. (Boolean)
IsForwardedIPAllowed runs the same address-identity checks as IsConnectionAllowed, that is Whitelist, Blacklist, active bans, GeoIP and CustomRules, but it skips the connection-scoped ones. RateLimit.MaxConnectionsPerIP and the internal connection counter are excluded on purpose, because they track sockets and a reverse proxy carries requests from many end clients over a small number of upstream connections. Calling it once per request is therefore safe and does not inflate any counter. The servers invoke it automatically after ResolveClientIP produces an address different from the peer, answering a rejected request with 403 Forbidden on the HTTP servers and dropping the connection for WebSocket and the other protocol handlers, so a manual call is only needed in custom request pipelines. The method is thread-safe. See Firewall: Real Client IP Behind a Reverse Proxy.
vClientIP := sgcWebSocketFirewall1.ResolveClientIP(Connection.PeerIP,
Connection.HeadersRequest);
if not sgcWebSocketFirewall1.IsForwardedIPAllowed(vClientIP) then
Connection.Disconnect;