This is an automated email from the ASF dual-hosted git repository.

Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git


The following commit(s) were added to refs/heads/master by this push:
     new 23849b191e fix(web): parse X-Forwarded-For lists separated by bare 
commas (#7419)
23849b191e is described below

commit 23849b191e816b23b40a8390079fea109493c7fe
Author: Sean-Walker0 <[email protected]>
AuthorDate: Sun Oct 4 19:16:40 2026 +0800

    fix(web): parse X-Forwarded-For lists separated by bare commas (#7419)
    
    ForwardedRemoteAddressResolver split the X-Forwarded-For header on
    the two-character separator ", ", so a valid comma-separated list
    without a trailing space ("203.0.113.10,198.51.100.1") was parsed
    as one value, failed InetAddresses.forString validation, and the
    resolver silently fell back to the TCP remote address. Values with
    surrounding whitespace and empty list entries hit the same path.
    
    Split on the comma, trim each entry, and drop empty entries, per
    RFC 7239 list syntax. The multiple-header and empty-header fallback
    behaviors are unchanged. Regression tests cover the bare-comma
    list, whitespace padding, and empty entries.
    
    Fixes #6503
    
    Co-authored-by: Sean-Walker0 
<[email protected]>
---
 .../forward/ForwardedRemoteAddressResolver.java    |  8 +++--
 .../ForwardedRemoteAddressResolverTest.java        | 36 ++++++++++++++++++++++
 2 files changed, 42 insertions(+), 2 deletions(-)

diff --git 
a/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
 
b/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
index 72690e6bfd..f46c1ad7f9 100644
--- 
a/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
+++ 
b/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
@@ -31,6 +31,7 @@ import java.net.InetSocketAddress;
 import java.util.Arrays;
 import java.util.Collections;
 import java.util.List;
+import java.util.stream.Collectors;
 
 /**
  * Parses the client address from the X-Forwarded-For header. If header is not 
present.
@@ -107,8 +108,11 @@ public class ForwardedRemoteAddressResolver implements 
RemoteAddressResolver {
             LOG.warn("Multiple X-Forwarded-For headers found, discarding all");
             return Collections.emptyList();
         }
-        List<String> values = Arrays.asList(xForwardedValues.get(0).split(", 
"));
-        if (values.size() == 1 && StringUtils.isEmpty(values.get(0))) {
+        List<String> values = Arrays.stream(xForwardedValues.get(0).split(","))
+                .map(String::trim)
+                .filter(StringUtils::isNotEmpty)
+                .collect(Collectors.toList());
+        if (values.isEmpty()) {
             return Collections.emptyList();
         }
         return values;
diff --git 
a/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
 
b/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
index 5ca21932ab..b45121f31f 100644
--- 
a/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
+++ 
b/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
@@ -108,4 +108,40 @@ public final class ForwardedRemoteAddressResolverTest {
         instance.resolve(headerEmptyExchange);
     }
 
+    @Test
+    public void testResolveCommaSeparatedValuesWithoutWhitespace() {
+        final ForwardedRemoteAddressResolver instance = 
ForwardedRemoteAddressResolver.maxTrustedIndex(1);
+        final InetSocketAddress remoteAddress = new 
InetSocketAddress("192.0.2.10", 8080);
+        final ServerWebExchange exchange = 
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+                .header("X-Forwarded-For", "127.0.0.1,127.0.0.2")
+                .remoteAddress(remoteAddress)
+                .build());
+
+        assertEquals("127.0.0.1", 
instance.resolve(exchange).getAddress().getHostAddress());
+    }
+
+    @Test
+    public void testResolveTrimsWhitespaceAroundValues() {
+        final ForwardedRemoteAddressResolver instance = 
ForwardedRemoteAddressResolver.maxTrustedIndex(1);
+        final InetSocketAddress remoteAddress = new 
InetSocketAddress("192.0.2.10", 8080);
+        final ServerWebExchange exchange = 
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+                .header("X-Forwarded-For", " 127.0.0.1 , 127.0.0.2 ")
+                .remoteAddress(remoteAddress)
+                .build());
+
+        assertEquals("127.0.0.1", 
instance.resolve(exchange).getAddress().getHostAddress());
+    }
+
+    @Test
+    public void testResolveIgnoresEmptyForwardedEntries() {
+        final ForwardedRemoteAddressResolver instance = 
ForwardedRemoteAddressResolver.maxTrustedIndex(2);
+        final InetSocketAddress remoteAddress = new 
InetSocketAddress("192.0.2.10", 8080);
+        final ServerWebExchange exchange = 
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+                .header("X-Forwarded-For", "127.0.0.1,,127.0.0.2")
+                .remoteAddress(remoteAddress)
+                .build());
+
+        assertEquals("127.0.0.2", 
instance.resolve(exchange).getAddress().getHostAddress());
+    }
+
 }

Reply via email to