nette / bootstrap

🅱 The simple way to configure and bootstrap your Nette application.
https://doc.nette.org/bootstrap
Other
668 stars 36 forks source link

Support for proxy #36

Closed JakubSvestka closed 9 years ago

JakubSvestka commented 9 years ago

http://forum.nette.org/cs/21450-nedostavam-skutecnou-ip-adresu

dg commented 9 years ago

This seems like security hole, because attacker can spoof HTTP header x-forwarded-for.

fprochazka commented 9 years ago

@kuba1999 using the new method with cookie is more secure than IP-only check.

JakubSvestka commented 9 years ago

ok. Thanks.