Verification of X-Real-IP header handling for authentication rate limiting
k3v1njp
HOBBYOP
14 days ago
Hello Railway Support,
We are preparing an employee authentication portal hosted on Railway.
Our Next.js frontend receives public HTTPS requests through Railway and communicates with our Django backend over Railway's private network.
We plan to use the X-Real-IP request header for login rate limiting. Could you please confirm:
- Does Railway's public HTTP proxy always overwrite a client-supplied
X-Real-IPheader with the actual connecting client's IP address? - Can an external client influence the value of
X-Real-IPreceived by our Next.js application? - Is there a recommended trusted client-IP mechanism for applications implementing authentication rate limiting on Railway?
We want to ensure that users cannot bypass the rate limiter by supplying forged forwarding headers.
Thank you.
Pinned Solution
14 days ago
X-Real-IPis written at the edge, so the header can't be spoofed by users.- The only way they can "influence" the value is by using a VPN.
- There are many ways to implement IP-based rate limiting. There isn't a specific one recommended just for Railway.
1 Replies
Railway
BOT
14 days ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 14 days ago
14 days ago
X-Real-IPis written at the edge, so the header can't be spoofed by users.- The only way they can "influence" the value is by using a VPN.
- There are many ways to implement IP-based rate limiting. There isn't a specific one recommended just for Railway.
Status changed to Solved 0x5b62656e5d • 14 days ago