X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/405b13d50e203958968427a2642bc18026a0c227..c4baa0a1c57c5b9aa5d08a5d3d1f50eca842d3f7:/lib/controller/proxy.go diff --git a/lib/controller/proxy.go b/lib/controller/proxy.go index d7381860ea..26d1859ec8 100644 --- a/lib/controller/proxy.go +++ b/lib/controller/proxy.go @@ -42,6 +42,14 @@ var dropHeaders = map[string]bool{ "Accept-Encoding": true, "Content-Encoding": true, "Transfer-Encoding": true, + + // Content-Length depends on encoding. + "Content-Length": true, + + // Defend against Rails vulnerability CVE-2023-22795 - + // we don't use this functionality anyway, so it costs us nothing. + // + "If-None-Match": true, } type ResponseFilter func(*http.Response, error) (*http.Response, error) @@ -60,10 +68,13 @@ func (p *proxy) Do( hdrOut[k] = v } } - xff := reqIn.RemoteAddr - if xffIn := reqIn.Header.Get("X-Forwarded-For"); xffIn != "" { - xff = xffIn + "," + xff + xff := "" + for _, xffIn := range reqIn.Header["X-Forwarded-For"] { + if xffIn != "" { + xff += xffIn + "," + } } + xff += reqIn.RemoteAddr hdrOut.Set("X-Forwarded-For", xff) if hdrOut.Get("X-Forwarded-Proto") == "" { hdrOut.Set("X-Forwarded-Proto", reqIn.URL.Scheme)