TrustedProxies is a OctoberCMS plugin to configure which headers to trust when handling requests. Tiis is useful when your site is behind a load balancer that terminates the SSL connection (for example Heroku or some AWS ELB configurations).
You can specify which header items to trust for the following items:
- forwarded for
- client IP
- client host
- client protocol
- client port
Install this plugin.
- Open your October back-end administration area and open Settings > Trusted Proxies.
- Enter the header items that you want to trust. See the plugin Documentation for detail on how to configure for common environments.
- Click Save
Usage on Heroku
If you are deploying your application on Heroku, set the trusted headers as described on the Heroku headers documentation.
|Trusted Proxies Setting||Value|
|Proxies to Trust||*|
|Trust Forwarded Header||X-Forwarded-For|
|Trust Client Protocol Header||X-Forwarded-Proto|
|Trust Client Forwarded Port||X-Forwarded-Port|
This plugin has not been reviewed yet.
First version of trustedproxies
Mar 30, 2017