Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

X_FORWARDED_FOR header fails to be interpreted when has multiple IPs #299

Open
1 task done
ngatti-tmm opened this issue Jan 3, 2024 · 0 comments
Open
1 task done
Labels
help wanted type:bug Something isn’t working.

Comments

@ngatti-tmm
Copy link

Describe the bug

If the header X_FORWARDED_FOR has more than 1 IP (for example when the requests goes through several reverse proxies) it seems the RSA plugin can't understand it.
An other issue is that when you click on "Add my IP" to the whitelist, it does not add anything.

Steps to Reproduce

  1. Configure a site under two reverse proxies configured to append X_FORWARDED_FOR headers
  2. Restrict access to the wordpress with RSA
  3. Add your public IP in the RSA whitelist
  4. Logout and try to browse the site. You will be blocked even when your IP is whitelisted.

Screenshots, screen recording, code snippet

No response

Environment information

No response

WordPress information

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@ngatti-tmm ngatti-tmm added the type:bug Something isn’t working. label Jan 3, 2024
@jeffpaul jeffpaul added this to the 7.6.0 milestone Jan 11, 2024
@jeffpaul jeffpaul modified the milestones: 7.6.0, Future Release Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted type:bug Something isn’t working.
Projects
None yet
Development

No branches or pull requests

2 participants