mirror of
https://github.com/MeoProject/lx-music-api-server.git
synced 2025-05-23 19:17:41 +08:00
fix: 修复一个逻辑漏洞
This commit is contained in:
parent
aa1894b66f
commit
52420696f8
2
main.py
2
main.py
@ -71,7 +71,7 @@ async def handle_before_request(app, handler):
|
|||||||
try:
|
try:
|
||||||
if config.read_config("common.reverse_proxy.allow_proxy") and request.headers.get(
|
if config.read_config("common.reverse_proxy.allow_proxy") and request.headers.get(
|
||||||
config.read_config("common.reverse_proxy.real_ip_header")):
|
config.read_config("common.reverse_proxy.real_ip_header")):
|
||||||
if not config.read_config("common.reverse_proxy.allow_public_ip") or utils.is_local_ip(request.remote):
|
if not (config.read_config("common.reverse_proxy.allow_public_ip") or utils.is_local_ip(request.remote)):
|
||||||
return handleResult({"code": 1, "msg": "不允许的公网ip转发", "data": None}, 403)
|
return handleResult({"code": 1, "msg": "不允许的公网ip转发", "data": None}, 403)
|
||||||
# proxy header
|
# proxy header
|
||||||
request.remote_addr = request.headers.get(config.read_config("common.reverse_proxy.real_ip_header"))
|
request.remote_addr = request.headers.get(config.read_config("common.reverse_proxy.real_ip_header"))
|
||||||
|
Loading…
x
Reference in New Issue
Block a user