Skip to content

fix(audit): record the trusted-proxy-aware client IP, never raw X-Forwarded-For (#877) - #883

Merged
alex-dembele merged 1 commit into
masterfrom
877-audit-ip
Oct 2, 2026
Merged

alex-dembele merged 1 commit into
masterfrom
877-audit-ip

Conversation

@alex-dembele

Copy link
Copy Markdown
Member

Closes #877

AuditService.LogFiber replaced c.IP() with the raw X-Forwarded-For header whenever the header was there, so any client could write the IP of its choice into auth_audit_logs (login, refresh, MFA, SSO events). It now records c.IP() only. Fiber resolves the forwarded address in c.IP() only when the peer is a configured trusted proxy (F-04).

The same raw read was in MFARateLimit and OAuthRateLimit (internal/middleware/auth.go). Neither is mounted anywhere today, but both now use c.IP() too, so the defect can't come back when someone wires them.

Verification

Honest remainders

…warded-For (#877)

Signed-off-by: alex-dembele <alexandredembele16@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security(audit): the auth audit trail records a client-chosen IP from raw X-Forwarded-For

1 participant