From 51f4108c733f102c94e7eaa846c6444054567095 Mon Sep 17 00:00:00 2001 From: kingschnulli Date: Wed, 23 Sep 2026 16:51:44 +0200 Subject: [PATCH 1/3] Remove unsafe static trusted proxy config --- compose.coolify.example.yaml | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/compose.coolify.example.yaml b/compose.coolify.example.yaml index 6b7923b..1a3c181 100644 --- a/compose.coolify.example.yaml +++ b/compose.coolify.example.yaml @@ -71,9 +71,6 @@ services: - vscode_server:/var/www/.vscode-server - codex_home:/var/www/.codex - configs: - - source: shopware_reverse_proxy - target: /var/www/html/config/packages/z-framework.yaml labels: - 'coolify.traefik.middlewares=authentik-forward-auth@file' @@ -86,16 +83,6 @@ services: - 'sshpiper.docker_sshd_cmd=/bin/bash' -configs: - shopware_reverse_proxy: - content: | - framework: - trusted_proxies: 'REMOTE_ADDR' - trusted_headers: - - 'x-forwarded-proto' - - 'x-forwarded-port' - - volumes: dev_runtime: shopware_html: From 240cfab092984699a5eb99e6b36feb761784c802 Mon Sep 17 00:00:00 2001 From: kingschnulli Date: Wed, 23 Sep 2026 16:52:09 +0200 Subject: [PATCH 2/3] Trust Coolify proxy for forwarded client IP --- scripts/dev-provision.sh | 45 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/scripts/dev-provision.sh b/scripts/dev-provision.sh index 7c11adf..18867d1 100755 --- a/scripts/dev-provision.sh +++ b/scripts/dev-provision.sh @@ -8,6 +8,51 @@ if ! id developer >/dev/null 2>&1; then exit 1 fi +# Trust only the Coolify reverse proxy for forwarded request metadata. +# Using Symfony's REMOTE_ADDR shortcut together with X-Forwarded-For would +# also trust direct requests from other containers on the project network. +proxy_host="${SHOPWARE_TRUSTED_PROXY_HOST:-coolify-proxy}" +trusted_proxy_file=/var/www/html/config/packages/z-framework.yaml +mapfile -t proxy_ips < <( + getent ahosts "$proxy_host" 2>/dev/null \ + | awk '$2 == "STREAM" && !seen[$1]++ { print $1 }' +) + +if (( ${#proxy_ips[@]} > 0 )); then + proxy_config_tmp="$(mktemp)" + + { + printf '%s\n' 'framework:' ' trusted_proxies:' + + for proxy_ip in "${proxy_ips[@]}"; do + printf " - '%s'\n" "$proxy_ip" + done + + printf '%s\n' \ + ' trusted_headers:' \ + " - 'x-forwarded-for'" \ + " - 'x-forwarded-proto'" \ + " - 'x-forwarded-port'" + } >"$proxy_config_tmp" + + if [[ ! -f "$trusted_proxy_file" ]] || ! cmp -s "$proxy_config_tmp" "$trusted_proxy_file"; then + sudo install -d -m 0755 "$(dirname "$trusted_proxy_file")" + sudo install -m 0644 "$proxy_config_tmp" "$trusted_proxy_file" + + if ! ( + cd /var/www/html + bin/console cache:clear + ); then + printf '%s\n' 'Warning: Shopware cache clear after trusted proxy configuration failed.' >&2 + fi + fi + + rm -f "$proxy_config_tmp" +else + printf 'Warning: trusted proxy host "%s" could not be resolved; forwarded client IP headers remain untrusted.\n' \ + "$proxy_host" >&2 +fi + # Persistent remote-development state is mounted here by the Coolify template. # Fresh named volumes are root-owned, so make their mount points writable by # Dockware's developer user while preserving any existing contents. From 350f4abf122ac56677996bcfbf55e11f528d0323 Mon Sep 17 00:00:00 2001 From: kingschnulli Date: Wed, 23 Sep 2026 16:52:43 +0200 Subject: [PATCH 3/3] Document trusted proxy provisioning --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 82aa2e4..50752ae 100644 --- a/README.md +++ b/README.md @@ -13,6 +13,7 @@ The runtime handles development plumbing only: - configure the default Git identity - provide Shopware CLI as the standard extension validation/build tool - mirror public sales-channel domains onto the internal `http://shop` origin for authenticated-gateway-free browser smoke tests +- configure Shopware to trust forwarded client metadata only from the Coolify reverse proxy - configure GitHub App credentials for HTTPS Git operations - clone repositories listed in `DEV_PLUGINS` into `custom/plugins` - leave existing Git working copies untouched on restart