H3-Fix: TRUST_PROXY konfigurierbar (H3: Rate-Limit-Bypass hinter Proxy geloest)

This commit is contained in:
Kühn
2026-09-10 17:07:14 +02:00
parent ad6983a49d
commit d43d1a3f34
3 changed files with 16 additions and 2 deletions

View File

@@ -48,8 +48,18 @@ const { startLDAPSync, isLDAPConfigured } = require('./ldapSync');
const app = express();
const PORT = process.env.PORT || 5000;
// Trust proxy for correct IP in rate limiting (Docker/Reverse Proxy)
app.set('trust proxy', 1);
// H3-Fix: Trust proxy konfigurierbar — hinter TLS-terminierendem Proxy (HAProxy)
// MUSS trust proxy aktiv sein, damit Express die echte Client-IP aus
// X-Forwarded-For liest (Rate-Limiting, Audit-Log). Bei direktem Port-Zugriff
// (ohne Proxy) muss es deaktiviert sein, sonst ist X-Forwarded-For spoofbar
// und das Rate-Limiting umgehbar.
// TRUST_PROXY=true → 1 Hop vertrauen (HAProxy/Nginx davor) ← Produktion
// TRUST_PROXY=false → keine Proxy-Header vertrauen ← direkter Zugriff
// unset → true in Produktion (Docker-Stack läuft hinter HAProxy)
const TRUST_PROXY = process.env.TRUST_PROXY !== undefined
? process.env.TRUST_PROXY === 'true'
: process.env.NODE_ENV === 'production';
app.set('trust proxy', TRUST_PROXY ? 1 : false);
// ============ Security Middleware ============
// P14: Validate CORS_ORIGIN - filter empty/invalid entries before using in CSP

View File

@@ -37,6 +37,8 @@ services:
- UPLOAD_MAX_MB=${UPLOAD_MAX_MB:-10}
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:3900}
- NODE_ENV=${NODE_ENV:-production}
# H3: Proxy-Header vertrauen (true hinter HAProxy/Nginx, false bei direktem Zugriff)
- TRUST_PROXY=${TRUST_PROXY:-true}
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
- SESSION_MAX_PER_USER=${SESSION_MAX_PER_USER:-5}
- SESSION_TTL_HOURS=${SESSION_TTL_HOURS:-168}

View File

@@ -24,6 +24,8 @@ services:
- SESSION_SECRET=${SESSION_SECRET:-}
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:5000}
- NODE_ENV=${NODE_ENV:-production}
# H3: Proxy-Header vertrauen (true hinter HAProxy/Nginx, false bei direktem Zugriff)
- TRUST_PROXY=${TRUST_PROXY:-true}
# Punkt 4: PostgreSQL (auto-started)
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
# Punkt 9: Session-Limitierung