2 months ago
We need the originating browser’s TCP source port — not destination port 443 — for a statutory API fraud-prevention header. Railway’s public documentation lists X-Real-IP, X-Request-Start and Railway request/edge IDs, but no source-port field.
Does Railway’s TLS-terminating HTTP edge provide an edge-overwritten, non-spoofable header or metadata containing the original client IP:port tuple (for example RFC 7239 Forwarded with for=IP:port), or is the source port unavailable to upstream HTTP services?
If it is unavailable, could a Railway employee please confirm that? X-Forwarded-Port, request.client.port and destination port 443 are not suitable because they are not the browser-to-edge source port.
Pinned Solution
2 months ago
Railway doesn't expose source ports. If you wish to do so, you can use a TCP proxy, but you'd need to handle TLS/HTTP(S) yourself.
1 Replies
2 months ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 2 months ago
2 months ago
Railway doesn't expose source ports. If you wish to do so, you can use a TCP proxy, but you'd need to handle TLS/HTTP(S) yourself.
Status changed to Solved 0x5b62656e5d • 19 days ago