a month ago
My Express application needs to trust the X-Forwarded-Proto and X-Real-IP headers only when they originate from the platform proxy. Which source IP addresses or CIDR blocks from the proxy are guaranteed and stable at the application socket level? If there is no such list, what trust configuration do you recommend, also taking into account access from private network services? Does the edge overwrite these two headers if sent by the client?
Pinned Solution
a month ago
https://docs.railway.com/guides/spa-routing-configuration#option-1-caddy-recommended
100.0.0.0/8 should be trusted.
2 Replies
a month ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 27 days ago
a month ago
https://docs.railway.com/guides/spa-routing-configuration#option-1-caddy-recommended
100.0.0.0/8 should be trusted.
0x5b62656e5d
https://docs.railway.com/guides/spa-routing-configuration#option-1-caddy-recommended `100.0.0.0/8` should be trusted.
a month ago
Ok, it works, thanks!
Status changed to Solved 0x5b62656e5d • 27 days ago
