From e7689459f25663e00b4f5814a3608872ff36b582 Mon Sep 17 00:00:00 2001 From: Alexandre Alapetite Date: Sun, 30 Jul 2023 12:59:18 +0200 Subject: Rework trusted proxies (#5549) * Rework trusted proxies Fix https://github.com/FreshRSS/FreshRSS/issues/5502 Follow-up of https://github.com/FreshRSS/FreshRSS/pull/3226 New environment variable `TRUSTED_PROXY`: set to 0 to disable, or to a list of trusted IP ranges compatible with https://httpd.apache.org/docs/current/mod/mod_remoteip.html#remoteiptrustedproxy New internal environment variable `CONN_REMOTE_ADDR` to remember the true IP address of the connection (e.g. last proxy), even when using mod_remoteip. Current working setups should not observe any significant change. * Minor whitespace * Safer trusted sources during install Rework of https://github.com/FreshRSS/FreshRSS/pull/5358 https://github.com/FreshRSS/FreshRSS/issues/5357 * Minor readme --- Docker/Dockerfile-Newest | 1 + 1 file changed, 1 insertion(+) (limited to 'Docker/Dockerfile-Newest') diff --git a/Docker/Dockerfile-Newest b/Docker/Dockerfile-Newest index 8c2d6eb71..c5615b512 100644 --- a/Docker/Dockerfile-Newest +++ b/Docker/Dockerfile-Newest @@ -57,6 +57,7 @@ ENV DATA_PATH '' ENV FRESHRSS_ENV '' ENV LISTEN '' ENV OIDC_ENABLED '' +ENV TRUSTED_PROXY '' ENTRYPOINT ["./Docker/entrypoint.sh"] -- cgit v1.2.3