Explorar o código

don't trust headers from external

Peter Bieringer %!s(int64=2) %!d(string=hai) anos
pai
achega
fadf281734
Modificáronse 1 ficheiros con 2 adicións e 0 borrados
  1. 2 0
      DOCUMENTATION.md

+ 2 - 0
DOCUMENTATION.md

@@ -355,6 +355,7 @@ RewriteRule ^/radicale$ /radicale/ [R,L]
     ProxyPassReverse http://localhost:5232/
     RequestHeader    set X-Script-Name /radicale
     RequestHeader    set X-Forwarded-Port "%{SERVER_PORT}s"
+    RequestHeader    unset X-Forwarded-Proto
     <If "%{HTTPS} =~ /on/">
     RequestHeader    set X-Forwarded-Proto "https"
     </If>
@@ -371,6 +372,7 @@ RewriteRule ^(.*)$ http://localhost:5232/$1 [P,L]
 # Set to directory of .htaccess file:
 RequestHeader set X-Script-Name /radicale
 RequestHeader set X-Forwarded-Port "%{SERVER_PORT}s"
+RequestHeader unset X-Forwarded-Proto
 <If "%{HTTPS} =~ /on/">
 RequestHeader set X-Forwarded-Proto "https"
 </If>