mirror of
https://github.com/9001/copyparty.git
synced 2025-08-17 09:02:15 -06:00
xff-warning: suggest proper /64 for ipv6
This commit is contained in:
parent
540664e0c2
commit
16462ee573
|
@ -20,6 +20,7 @@ import time
|
||||||
import uuid
|
import uuid
|
||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
from operator import itemgetter
|
from operator import itemgetter
|
||||||
|
from ipaddress import IPv6Network
|
||||||
|
|
||||||
import jinja2 # typechk
|
import jinja2 # typechk
|
||||||
|
|
||||||
|
@ -387,11 +388,12 @@ class HttpCli(object):
|
||||||
t += ' Note: if you are behind cloudflare, then this default header is not a good choice; please first make sure your local reverse-proxy (if any) does not allow non-cloudflare IPs from providing cf-* headers, and then add this additional global setting: "--xff-hdr=cf-connecting-ip"'
|
t += ' Note: if you are behind cloudflare, then this default header is not a good choice; please first make sure your local reverse-proxy (if any) does not allow non-cloudflare IPs from providing cf-* headers, and then add this additional global setting: "--xff-hdr=cf-connecting-ip"'
|
||||||
else:
|
else:
|
||||||
t += ' Note: depending on your reverse-proxy, and/or WAF, and/or other intermediates, you may want to read the true client IP from another header by also specifying "--xff-hdr=SomeOtherHeader"'
|
t += ' Note: depending on your reverse-proxy, and/or WAF, and/or other intermediates, you may want to read the true client IP from another header by also specifying "--xff-hdr=SomeOtherHeader"'
|
||||||
zs = (
|
|
||||||
".".join(pip.split(".")[:2]) + "."
|
if "." in pip:
|
||||||
if "." in pip
|
zs = ".".join(pip.split(".")[:2]) + ".0.0/16"
|
||||||
else ":".join(pip.split(":")[:4]) + ":"
|
else:
|
||||||
) + "0.0/16"
|
zs = IPv6Network(pip + "/64", False).compressed
|
||||||
|
|
||||||
zs2 = ' or "--xff-src=lan"' if self.conn.xff_lan.map(pip) else ""
|
zs2 = ' or "--xff-src=lan"' if self.conn.xff_lan.map(pip) else ""
|
||||||
self.log(t % (self.args.xff_hdr, pip, cli_ip, zso, zs, zs2), 3)
|
self.log(t % (self.args.xff_hdr, pip, cli_ip, zso, zs, zs2), 3)
|
||||||
self.bad_xff = True
|
self.bad_xff = True
|
||||||
|
|
Loading…
Reference in a new issue