fix(sub): never use X-Real-IP as the subscription host (#6608)

ResolveRequest and the panel's resolveHost fell back to X-Real-IP for the host when a trusted proxy sent no X-Forwarded-Host. X-Real-IP names the visitor, so behind nginx with only that header set, subscription and exported links advertised the subscriber's own public IP as the server.

The host now comes from a trusted X-Forwarded-Host, else the dialed request Host. X-Real-IP stays a client-IP source only.

Fixes #6589.
This commit is contained in:
mrchatam
2026-09-26 22:43:46 +03:30
committed by GitHub
parent 66df77665f
commit 169cd86e00
4 changed files with 54 additions and 16 deletions
+2 -8
View File
@@ -442,11 +442,8 @@ func (a *InboundController) importInbound(c *gin.Context) {
notifyClientsChanged()
}
// resolveHost mirrors what sub.SubService.ResolveRequest does for the host
// field: prefers X-Forwarded-Host (first entry of any list, port stripped),
// then X-Real-IP, then the host portion of c.Request.Host. Keeping it in the
// controller layer means the service interface stays HTTP-agnostic — service
// methods receive a plain host string instead of a *gin.Context.
// resolveHost mirrors SubService.ResolveRequest's host: trusted X-Forwarded-Host,
// else the dialed request Host. X-Real-IP names the visitor, not the panel (#6589).
func resolveHost(c *gin.Context) string {
if isTrustedForwardedRequest(c) {
if h := strings.TrimSpace(c.GetHeader("X-Forwarded-Host")); h != "" {
@@ -458,9 +455,6 @@ func resolveHost(c *gin.Context) string {
}
return h
}
if h := c.GetHeader("X-Real-IP"); h != "" {
return h
}
}
if h, _, err := net.SplitHostPort(c.Request.Host); err == nil {
return h
+27
View File
@@ -32,3 +32,30 @@ func TestGetRemoteIpHonorsForwardedHeadersFromTrustedLoopbackProxy(t *testing.T)
t.Fatalf("remote IP = %q, want forwarded client IP", got)
}
}
func TestResolveHostPrefersForwardedHostOverRealIP(t *testing.T) {
gin.SetMode(gin.TestMode)
c, _ := gin.CreateTestContext(httptest.NewRecorder())
c.Request = httptest.NewRequest(http.MethodGet, "/", nil)
c.Request.Host = "panel.example.com:2053"
c.Request.RemoteAddr = "127.0.0.1:12345"
c.Request.Header.Set("X-Forwarded-Host", "sub.example.net:443")
c.Request.Header.Set("X-Real-IP", "198.51.100.7")
if got := resolveHost(c); got != "sub.example.net" {
t.Fatalf("resolveHost = %q, want X-Forwarded-Host", got)
}
}
func TestResolveHostIgnoresRealIPFromTrustedProxy(t *testing.T) {
gin.SetMode(gin.TestMode)
c, _ := gin.CreateTestContext(httptest.NewRecorder())
c.Request = httptest.NewRequest(http.MethodGet, "/", nil)
c.Request.Host = "panel.example.com:2053"
c.Request.RemoteAddr = "127.0.0.1:12345"
c.Request.Header.Set("X-Real-IP", "198.51.100.7")
if got := resolveHost(c); got != "panel.example.com" {
t.Fatalf("resolveHost = %q, want request host (not X-Real-IP)", got)
}
}