-
Bug
-
Resolution: Done-Errata
-
Major
-
None
-
False
-
None
-
False
-
---
-
-
This PR introduces a way to determine if a trusted proxy has forwarded a request behind a proxy. It implements a custom header (`X-Forwarded-Trusted-Proxy`) that allows request processing to verify the presence of this header, indicating the request originated from a trusted source.
To prevent forgery, any incoming request containing this custom header has it removed before further processing.
CC @shawkins
- links to
-
RHSA-2025:0900 Red Hat build of Quarkus 3.15.3 release and security update