Просмотр исходного кода

don't trust headers from external

Peter Bieringer 2 лет назад
Родитель
Сommit
fadf281734
1 измененных файлов с 2 добавлено и 0 удалено
  1. 2 0
      DOCUMENTATION.md

+ 2 - 0
DOCUMENTATION.md

@@ -355,6 +355,7 @@ RewriteRule ^/radicale$ /radicale/ [R,L]
     ProxyPassReverse http://localhost:5232/
     RequestHeader    set X-Script-Name /radicale
     RequestHeader    set X-Forwarded-Port "%{SERVER_PORT}s"
+    RequestHeader    unset X-Forwarded-Proto
     <If "%{HTTPS} =~ /on/">
     RequestHeader    set X-Forwarded-Proto "https"
     </If>
@@ -371,6 +372,7 @@ RewriteRule ^(.*)$ http://localhost:5232/$1 [P,L]
 # Set to directory of .htaccess file:
 RequestHeader set X-Script-Name /radicale
 RequestHeader set X-Forwarded-Port "%{SERVER_PORT}s"
+RequestHeader unset X-Forwarded-Proto
 <If "%{HTTPS} =~ /on/">
 RequestHeader set X-Forwarded-Proto "https"
 </If>