H3-Fix: TRUST_PROXY konfigurierbar (H3: Rate-Limit-Bypass hinter Proxy geloest)
This commit is contained in:
@@ -48,8 +48,18 @@ const { startLDAPSync, isLDAPConfigured } = require('./ldapSync');
|
||||
const app = express();
|
||||
const PORT = process.env.PORT || 5000;
|
||||
|
||||
// Trust proxy for correct IP in rate limiting (Docker/Reverse Proxy)
|
||||
app.set('trust proxy', 1);
|
||||
// H3-Fix: Trust proxy konfigurierbar — hinter TLS-terminierendem Proxy (HAProxy)
|
||||
// MUSS trust proxy aktiv sein, damit Express die echte Client-IP aus
|
||||
// X-Forwarded-For liest (Rate-Limiting, Audit-Log). Bei direktem Port-Zugriff
|
||||
// (ohne Proxy) muss es deaktiviert sein, sonst ist X-Forwarded-For spoofbar
|
||||
// und das Rate-Limiting umgehbar.
|
||||
// TRUST_PROXY=true → 1 Hop vertrauen (HAProxy/Nginx davor) ← Produktion
|
||||
// TRUST_PROXY=false → keine Proxy-Header vertrauen ← direkter Zugriff
|
||||
// unset → true in Produktion (Docker-Stack läuft hinter HAProxy)
|
||||
const TRUST_PROXY = process.env.TRUST_PROXY !== undefined
|
||||
? process.env.TRUST_PROXY === 'true'
|
||||
: process.env.NODE_ENV === 'production';
|
||||
app.set('trust proxy', TRUST_PROXY ? 1 : false);
|
||||
|
||||
// ============ Security Middleware ============
|
||||
// P14: Validate CORS_ORIGIN - filter empty/invalid entries before using in CSP
|
||||
|
||||
Reference in New Issue
Block a user