Browse Source

fix: respect forward_headers_strategy for client IP in audit logs

Remove redundant manual X-Forwarded-For header parsing in
RestAuthenticationDetails. The getClientIP() method duplicated
functionality already provided by Spring's ForwardedHeaderFilter
when server.forward_headers_strategy is configured.

Now uses request.getRemoteAddr() directly, which respects the
configured forward_headers_strategy setting (default: framework).

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
pull/14953/head
Dmytro Skarzhynets 8 months ago
parent
commit
74ef364f33
No known key found for this signature in database GPG Key ID: 2B51652F224037DF
  1. 10
      application/src/main/java/org/thingsboard/server/service/security/auth/rest/RestAuthenticationDetails.java

10
application/src/main/java/org/thingsboard/server/service/security/auth/rest/RestAuthenticationDetails.java

@ -29,18 +29,10 @@ public class RestAuthenticationDetails implements Serializable {
private final Client userAgent;
public RestAuthenticationDetails(HttpServletRequest request) {
this.clientAddress = getClientIP(request);
this.clientAddress = request.getRemoteAddr();
this.userAgent = getUserAgent(request);
}
private static String getClientIP(HttpServletRequest request) {
String xfHeader = request.getHeader("X-Forwarded-For");
if (xfHeader == null) {
return request.getRemoteAddr();
}
return xfHeader.split(",")[0];
}
private static Client getUserAgent(HttpServletRequest request) {
Parser uaParser = new Parser();
return uaParser.parse(request.getHeader("User-Agent"));

Loading…
Cancel
Save