Verification of X-Real-IP header handling for authentication rate limiting
k3v1njp
HOBBYOP

14 days ago

Hello Railway Support,

We are preparing an employee authentication portal hosted on Railway.

Our Next.js frontend receives public HTTPS requests through Railway and communicates with our Django backend over Railway's private network.

We plan to use the X-Real-IP request header for login rate limiting. Could you please confirm:

  1. Does Railway's public HTTP proxy always overwrite a client-supplied X-Real-IP header with the actual connecting client's IP address?
  2. Can an external client influence the value of X-Real-IP received by our Next.js application?
  3. Is there a recommended trusted client-IP mechanism for applications implementing authentication rate limiting on Railway?

We want to ensure that users cannot bypass the rate limiter by supplying forged forwarding headers.

Thank you.

Solved$10 Bounty

Pinned Solution

  1. X-Real-IP is written at the edge, so the header can't be spoofed by users.
  2. The only way they can "influence" the value is by using a VPN.
  3. There are many ways to implement IP-based rate limiting. There isn't a specific one recommended just for Railway.

1 Replies

Railway
BOT

14 days ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 14 days ago


  1. X-Real-IP is written at the edge, so the header can't be spoofed by users.
  2. The only way they can "influence" the value is by using a VPN.
  3. There are many ways to implement IP-based rate limiting. There isn't a specific one recommended just for Railway.

Status changed to Solved 0x5b62656e5d • 14 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...