From bb3db2e326933f59e73ca5536fc783faed5d51ee Mon Sep 17 00:00:00 2001 From: Darren Yu Date: Tue, 12 Aug 2025 09:35:36 +0800 Subject: [PATCH] fix(middleware): left deafult `ProxyHeader` config item as blank to reduce risk of fake xff (#2760) --- application/migrator/conf/defaults.go | 2 +- pkg/conf/types.go | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/application/migrator/conf/defaults.go b/application/migrator/conf/defaults.go index 4ecfd2b..d916027 100644 --- a/application/migrator/conf/defaults.go +++ b/application/migrator/conf/defaults.go @@ -22,7 +22,7 @@ var SystemConfig = &system{ Debug: false, Mode: "master", Listen: ":5212", - ProxyHeader: "X-Forwarded-For", + ProxyHeader: "", } // CORSConfig 跨域配置 diff --git a/pkg/conf/types.go b/pkg/conf/types.go index e5a53b4..509ceca 100644 --- a/pkg/conf/types.go +++ b/pkg/conf/types.go @@ -114,7 +114,7 @@ var SystemConfig = &System{ Debug: false, Mode: MasterMode, Listen: ":5212", - ProxyHeader: "X-Forwarded-For", + ProxyHeader: "", LogLevel: "info", }