This is an automated email from the ASF dual-hosted git repository.
Aias00 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/shenyu.git
The following commit(s) were added to refs/heads/master by this push:
new 23849b191e fix(web): parse X-Forwarded-For lists separated by bare
commas (#7419)
23849b191e is described below
commit 23849b191e816b23b40a8390079fea109493c7fe
Author: Sean-Walker0 <[email protected]>
AuthorDate: Sun Oct 4 19:16:40 2026 +0800
fix(web): parse X-Forwarded-For lists separated by bare commas (#7419)
ForwardedRemoteAddressResolver split the X-Forwarded-For header on
the two-character separator ", ", so a valid comma-separated list
without a trailing space ("203.0.113.10,198.51.100.1") was parsed
as one value, failed InetAddresses.forString validation, and the
resolver silently fell back to the TCP remote address. Values with
surrounding whitespace and empty list entries hit the same path.
Split on the comma, trim each entry, and drop empty entries, per
RFC 7239 list syntax. The multiple-header and empty-header fallback
behaviors are unchanged. Regression tests cover the bare-comma
list, whitespace padding, and empty entries.
Fixes #6503
Co-authored-by: Sean-Walker0
<[email protected]>
---
.../forward/ForwardedRemoteAddressResolver.java | 8 +++--
.../ForwardedRemoteAddressResolverTest.java | 36 ++++++++++++++++++++++
2 files changed, 42 insertions(+), 2 deletions(-)
diff --git
a/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
b/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
index 72690e6bfd..f46c1ad7f9 100644
---
a/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
+++
b/shenyu-web/src/main/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolver.java
@@ -31,6 +31,7 @@ import java.net.InetSocketAddress;
import java.util.Arrays;
import java.util.Collections;
import java.util.List;
+import java.util.stream.Collectors;
/**
* Parses the client address from the X-Forwarded-For header. If header is not
present.
@@ -107,8 +108,11 @@ public class ForwardedRemoteAddressResolver implements
RemoteAddressResolver {
LOG.warn("Multiple X-Forwarded-For headers found, discarding all");
return Collections.emptyList();
}
- List<String> values = Arrays.asList(xForwardedValues.get(0).split(",
"));
- if (values.size() == 1 && StringUtils.isEmpty(values.get(0))) {
+ List<String> values = Arrays.stream(xForwardedValues.get(0).split(","))
+ .map(String::trim)
+ .filter(StringUtils::isNotEmpty)
+ .collect(Collectors.toList());
+ if (values.isEmpty()) {
return Collections.emptyList();
}
return values;
diff --git
a/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
b/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
index 5ca21932ab..b45121f31f 100644
---
a/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
+++
b/shenyu-web/src/test/java/org/apache/shenyu/web/forward/ForwardedRemoteAddressResolverTest.java
@@ -108,4 +108,40 @@ public final class ForwardedRemoteAddressResolverTest {
instance.resolve(headerEmptyExchange);
}
+ @Test
+ public void testResolveCommaSeparatedValuesWithoutWhitespace() {
+ final ForwardedRemoteAddressResolver instance =
ForwardedRemoteAddressResolver.maxTrustedIndex(1);
+ final InetSocketAddress remoteAddress = new
InetSocketAddress("192.0.2.10", 8080);
+ final ServerWebExchange exchange =
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+ .header("X-Forwarded-For", "127.0.0.1,127.0.0.2")
+ .remoteAddress(remoteAddress)
+ .build());
+
+ assertEquals("127.0.0.1",
instance.resolve(exchange).getAddress().getHostAddress());
+ }
+
+ @Test
+ public void testResolveTrimsWhitespaceAroundValues() {
+ final ForwardedRemoteAddressResolver instance =
ForwardedRemoteAddressResolver.maxTrustedIndex(1);
+ final InetSocketAddress remoteAddress = new
InetSocketAddress("192.0.2.10", 8080);
+ final ServerWebExchange exchange =
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+ .header("X-Forwarded-For", " 127.0.0.1 , 127.0.0.2 ")
+ .remoteAddress(remoteAddress)
+ .build());
+
+ assertEquals("127.0.0.1",
instance.resolve(exchange).getAddress().getHostAddress());
+ }
+
+ @Test
+ public void testResolveIgnoresEmptyForwardedEntries() {
+ final ForwardedRemoteAddressResolver instance =
ForwardedRemoteAddressResolver.maxTrustedIndex(2);
+ final InetSocketAddress remoteAddress = new
InetSocketAddress("192.0.2.10", 8080);
+ final ServerWebExchange exchange =
MockServerWebExchange.from(MockServerHttpRequest.post("localhost")
+ .header("X-Forwarded-For", "127.0.0.1,,127.0.0.2")
+ .remoteAddress(remoteAddress)
+ .build());
+
+ assertEquals("127.0.0.2",
instance.resolve(exchange).getAddress().getHostAddress());
+ }
+
}