Uploaded image for project: 'Blesta Core'
  1. Blesta Core
  2. CORE-2915

Shared Login: Allow IPs from the x-forwarded-for header

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 4.5.0-b1
    • Component/s: None
    • Labels:
      None

      Description

      The Shared Login plugin references a user's IP address from the server's REMOTE_ADDR, but this is not reliable in cases where the server is behind a proxy.

      Update references to the IP address and REMOTE_ADDR usage to use Blesta's internal Requestor service to determine the IP address of the user.

        Issue Links

          Activity

          tyson Tyson Phillips (Inactive) created issue -
          tyson Tyson Phillips (Inactive) made changes -
          Field Original Value New Value
          Story Points 1
          tyson Tyson Phillips (Inactive) made changes -
          Sprint 4.5.0 Sprint 2 [ 67 ]
          tyson Tyson Phillips (Inactive) made changes -
          Rank Ranked higher
          tyson Tyson Phillips (Inactive) made changes -
          Link This issue is blocked by CORE-2349 [ CORE-2349 ]
          tyson Tyson Phillips (Inactive) made changes -
          Summary Shared Login: Allow IP from the x-forwarded-for header Shared Login: Allow IPs from the x-forwarded-for header
          Automated transition triggered when Tyson Phillips (Inactive) created a branch in Stash -
          Status Open [ 1 ] In Progress [ 3 ]
          Automated transition triggered when Tyson Phillips (Inactive) created pull request #3 in Stash -
          Status In Progress [ 3 ] In Review [ 5 ]
          Resolution Fixed [ 1 ]
          tyson Tyson Phillips (Inactive) made changes -
          Remaining Estimate 0 minutes [ 0 ]
          Time Spent 30 minutes [ 1800 ]
          Worklog Id 11677 [ 11677 ]
          tyson Tyson Phillips (Inactive) made changes -
          Sprint 4.5.0 Sprint 2 [ 67 ] 4.5.0 Sprint 2, 4.5.0 Sprint 3 [ 67, 74 ]
          tyson Tyson Phillips (Inactive) made changes -
          Rank Ranked higher
          Automated transition triggered when Tyson Phillips (Inactive) merged pull request #3 in Stash -
          Status In Review [ 5 ] Closed [ 6 ]

            People

            • Assignee:
              tyson Tyson Phillips (Inactive)
              Reporter:
              tyson Tyson Phillips (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Fix Release Date:
                31/Jan/19

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 30 minutes
                30m

                  Agile