Skip to content
Discussion options

You must be logged in to vote

It is intentional. The lack of configuration is also intentional - that just leads to insecure configurations, as unfortunately very few people understand the implications and most will blindly trust user-controlled headers.

Bottom line is, anyone competent enough to know when and how it's safe to utilize a proxy-propagated client IP value, should also know how to overwrite REMOTE_ADDR even before it reaches the PHP process.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by narfbg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants