Skip to main content

resolve_request_origin

Function resolve_request_origin 

Source
pub fn resolve_request_origin(
    headers: &HeaderMap,
    trust_proxy_headers: bool,
    trusted_proxies: &[IpNet],
    fallback_bind_address: SocketAddr,
    connect_info: Option<SocketAddr>,
) -> RequestOrigin
Expand description

Resolves forwarded metadata only for TCP peers in trusted_proxies with proxy mode enabled.

Forwarded addresses must all parse as IP addresses. The rightmost untrusted address identifies the client, after skipping trusted proxy hops. Missing, malformed or entirely trusted chains fall back to the TCP peer. IPv4-mapped IPv6 addresses use their IPv4 identity and require an IPv4 trusted CIDR. Without a peer, forwarding is disabled.

The trusted edge must overwrite forwarded host and protocol with single values. Invalid or repeated values fall back to Host and HTTP respectively. Address traversal follows NGINX’s recursive trust rule.