Skip to content

Commit 5cd2e28

Browse files
authored
Update default.conf to include X-Forwarded-Host overwrite as default
This prevents X-Forwarded forgery if upstream services trust the headers set by nginx, and downstream clients can set falsified forward headers.
1 parent 74ec02a commit 5cd2e28

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

default.conf

+1
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ server {
1616
proxy_set_header Host $http_host;
1717
proxy_set_header X-Real-IP $remote_addr;
1818
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
19+
proxy_set_header X-Forwarded-Host $http_host;
1920
proxy_set_header X-Forwarded-Proto $scheme;
2021
# add support for websockets
2122
proxy_set_header Upgrade $http_upgrade;

0 commit comments

Comments
 (0)