TsgcWebSocketFirewall › Properties › ForwardedHeaders
Resolves the real client address from the X-Forwarded-For and X-Real-IP request headers when the server runs behind a trusted reverse proxy.
property ForwardedHeaders: TsgcFirewallForwardedHeaders read FForwardedHeaders write SetForwardedHeaders;
—
Set ForwardedHeaders.Enabled to True when a reverse proxy (Caddy, NGINX, HAProxy) sits in front of the server, so the firewall works against the end client instead of against the proxy address. The feature is disabled by default and nothing changes on upgrade until it is switched on. Headers are honoured only when the immediate peer matches an entry in TrustedProxies, a TStringList of IP addresses and CIDR ranges using the same syntax as Whitelist.IPs. While that list is empty the headers are ignored entirely, which is the anti-spoofing gate of the feature: without a trust anchor any client could claim any address, forge audit entries and evade a Blacklist entry or an active ban. Mode selects which headers are read, fwmXForwardedFor, fwmXRealIP or fwmBoth. In the X-Forwarded-For chain every proxy appends the address of the peer it received the request from, so the last TrustedHops entries are the ones the trusted proxies wrote and the first of those is taken as the client address; anything further left was supplied by the client and is attacker controlled, so it is never used, and a chain holding fewer entries than TrustedHops does not match the declared topology, fails closed and leaves the peer address in place. When resolution succeeds the connection IP property is overwritten with the real client address and the original socket address remains available as PeerIP. Resolution runs per request, not per connection, because a proxy reuses one upstream connection for requests from different end clients, and the per-request verdict comes from IsForwardedIPAllowed. Note that the connect-time check still runs against the socket peer, so the proxy address itself must be allowed by Whitelist and Blacklist, and that RateLimit.MaxConnectionsPerIP keeps counting the proxy sockets because it is connection scoped. Defaults: Enabled=False, Mode=fwmBoth, TrustedHops=1. See Firewall: Real Client IP Behind a Reverse Proxy for worked Caddy and NGINX configurations.
sgcWebSocketFirewall1.ForwardedHeaders.Enabled := True;
sgcWebSocketFirewall1.ForwardedHeaders.TrustedProxies.Add('127.0.0.1');
sgcWebSocketFirewall1.ForwardedHeaders.Mode := fwmBoth;
sgcWebSocketFirewall1.ForwardedHeaders.TrustedHops := 1;
// the proxy itself must survive the connect-time check
sgcWebSocketFirewall1.Whitelist.Enabled := True;
sgcWebSocketFirewall1.Whitelist.IPs.Add('127.0.0.1');