Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ WebRootPath: "/opt/ss14_admin/bin/wwwroot"

ForwardProxies:
- 127.0.0.1
- 172.16.0.0/12 # Supports CIDR notation for subnets (Docker)

Auth:
Authority: "https://central.spacestation14.io/web/"
Expand Down
23 changes: 21 additions & 2 deletions SS14.Admin/Startup.cs
Original file line number Diff line number Diff line change
Expand Up @@ -99,9 +99,28 @@
ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto,
};

foreach (var ip in Configuration.GetSection("ForwardProxies").Get<string[]>() ?? Array.Empty<string>())
foreach (var entry in Configuration.GetSection("ForwardProxies").Get<string[]>() ?? Array.Empty<string>())
{
forwardedHeadersOptions.KnownProxies.Add(IPAddress.Parse(ip));
// Try to parse as CIDR notation first (e.g., 192.168.1.0/24)
if (IPHelper.TryParseIpOrCidr(entry, out var parsed))
{
var (ipAddress, prefixLength) = parsed;
if (prefixLength.HasValue)
{
// It's a CIDR subnet, add to KnownNetworks
var network = new Microsoft.AspNetCore.HttpOverrides.IPNetwork(ipAddress, prefixLength.Value);

Check warning on line 111 in SS14.Admin/Startup.cs

View workflow job for this annotation

GitHub Actions / build

'IPNetwork' is obsolete: 'Please use System.Net.IPNetwork instead. For more information, visit https://aka.ms/aspnet/deprecate/005.' (https://aka.ms/aspnet/deprecate/005)

Check warning on line 111 in SS14.Admin/Startup.cs

View workflow job for this annotation

GitHub Actions / build

'IPNetwork' is obsolete: 'Please use System.Net.IPNetwork instead. For more information, visit https://aka.ms/aspnet/deprecate/005.' (https://aka.ms/aspnet/deprecate/005)
forwardedHeadersOptions.KnownNetworks.Add(network);

Check warning on line 112 in SS14.Admin/Startup.cs

View workflow job for this annotation

GitHub Actions / build

'ForwardedHeadersOptions.KnownNetworks' is obsolete: 'Please use KnownIPNetworks instead. For more information, visit https://aka.ms/aspnet/deprecate/005.' (https://aka.ms/aspnet/deprecate/005)

Check warning on line 112 in SS14.Admin/Startup.cs

View workflow job for this annotation

GitHub Actions / build

'ForwardedHeadersOptions.KnownNetworks' is obsolete: 'Please use KnownIPNetworks instead. For more information, visit https://aka.ms/aspnet/deprecate/005.' (https://aka.ms/aspnet/deprecate/005)
}
else
{
// It's a single IP address, add to KnownProxies
forwardedHeadersOptions.KnownProxies.Add(ipAddress);
}
}
else
{
throw new InvalidOperationException($"Invalid IP address or CIDR notation in ForwardProxies: {entry}");
}
}

app.UseForwardedHeaders(forwardedHeadersOptions);
Expand Down
1 change: 1 addition & 0 deletions SS14.Admin/appsettings.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ Serilog:

ForwardProxies:
- 127.0.0.1
# - 172.16.0.0/12 # Supports CIDR notation for subnets (Docker)

AuthServer: "https://central.spacestation14.io/auth"
AllowedHosts: "*"