Skip to content

Fix forwarded client IP handling behind Coolify - #1

Merged
kingschnulli merged 3 commits into
mainfrom
fix/trusted-client-ip
Sep 23, 2026
Merged

kingschnulli merged 3 commits into
mainfrom
fix/trusted-client-ip

Conversation

@kingschnulli

Copy link
Copy Markdown
Contributor

What changed

  • resolve coolify-proxy from inside the Shopware container at boot
  • trust only the resolved proxy IP(s) instead of Symfony's REMOTE_ADDR shortcut
  • enable x-forwarded-for in addition to the existing proto/port headers
  • regenerate the Shopware framework config only when the resolved proxy address changes
  • clear Shopware cache after a trusted-proxy config change
  • remove the static Compose-mounted proxy config

Why

The firewall uses Shopware/Symfony Request::getClientIp(). Without trusting X-Forwarded-For, external requests are reported as the Docker-side Traefik IP (for example 172.21.0.3), so blocking that address can affect multiple visitors. Trusting REMOTE_ADDR while enabling forwarded-for would also allow direct internal callers to spoof the forwarded client IP.

@kingschnulli
kingschnulli merged commit 140b04b into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant