From f00550263a1c657b6ed7dbc5b6a0c16870251618 Mon Sep 17 00:00:00 2001 From: Guus der Kinderen Date: Fri, 25 Sep 2026 12:25:39 +0200 Subject: [PATCH] fixes #249: Do not trust client-provided forwarded headers for the IP address check The IP address used to check against the list of allowed IP addresses was taken from the 'X-Forwarded-For' header (and some variants) when present. As any client can set that header, the check could easily be bypassed. The address is now obtained from the request's remote address only. The REST API is served by the admin console's web server, which (when configured to do so) replaces that address with the value from forwarded headers. Since Openfire 5.1.0 (OF-3261), it can be configured to do so only for requests from trusted proxies. This plugin now requires Openfire 5.1.0 or later. The admin console page of the REST API shows a warning when the IP address check is enabled, while the admin console uses forwarded headers without a list of trusted proxies. --- changelog.html | 2 ++ plugin.xml | 2 +- pom.xml | 2 +- readme.md | 24 ++++++++++++++ .../openfire/plugin/rest/AuthFilter.java | 15 +++------ .../plugin/rest/RESTServicePlugin.java | 21 ++++++++++++ .../rest/service/UserServiceLegacy.java | 15 +++------ src/web/images/warning-16x16.gif | Bin 0 -> 580 bytes src/web/rest-api.jsp | 30 ++++++++++++++++-- 9 files changed, 84 insertions(+), 27 deletions(-) create mode 100644 src/web/images/warning-16x16.gif diff --git a/changelog.html b/changelog.html index fad07088da..82d83c4b49 100644 --- a/changelog.html +++ b/changelog.html @@ -46,9 +46,11 @@

1.12.1 (to be determined)