cloudsidedev / appside

Multitenant environment automation.
http://cloudside.ch
GNU Affero General Public License v3.0
38 stars 7 forks source link

Varnish: Don't allow cache purge if the `X-Forwarded-For` header is set. #72

Closed ocean90 closed 7 years ago

ocean90 commented 7 years ago

If the header is set we're handling a request by an external client. See https://info.varnish-software.com/blog/failure-to-purge-a-story-about-client.ip-and-proxies for background.

See #47.