Never trust X-Forwarded-For, Forwarded, X-Real-IP, or CDN client IP headers from arbitrary clients.
The library uses this rule:
- Start with
REMOTE_ADDR. - If
REMOTE_ADDRis not trusted, ignore all forwarded headers. - If
REMOTE_ADDRis trusted, parse only configured trusted headers. - Validate every IP address.
- Pick the first untrusted upstream address as the client address.
Common presets exist for Cloudflare, Fastly, Akamai, AWS load balancers, and generic Nginx reverse proxies. Keep provider CIDR ranges current in your application when using CDN presets.