Connections
raynner
FREEOP

a month ago

My Express application needs to trust the X-Forwarded-Proto and X-Real-IP headers only when they originate from the platform proxy. Which source IP addresses or CIDR blocks from the proxy are guaranteed and stable at the application socket level? If there is no such list, what trust configuration do you recommend, also taking into account access from private network services? Does the edge overwrite these two headers if sent by the client?

Solved$10 Bounty

2 Replies

Railway
BOT

a month ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 27 days ago



0x5b62656e5d

https://docs.railway.com/guides/spa-routing-configuration#option-1-caddy-recommended `100.0.0.0/8` should be trusted.

raynner
FREEOP

a month ago

Ok, it works, thanks!


Status changed to Solved 0x5b62656e5d • 27 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...