You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The new getClientIp function uses the proxy-addr library to validate trusted proxies and extract the client IP. Ensure that the logic correctly handles edge cases, such as malformed headers, IPv6 addresses, and empty or misconfigured trustedProxies arrays. Also, verify that the fallback to the remote address is secure and reliable.
exportfunctiongetClientIp(req,trustedProxies: string[]=[]): string{if(req==null){returnnull}constremoteAddress=(req.connection ? req.connection.remoteAddress : null)||(req.socket ? req.socket.remoteAddress : null)||nullconstforwarded=req.headers['x-forwarded-for']if(forwarded&&remoteAddress){consttrust=proxyaddr.compile(trustedProxies)if(trust(remoteAddress)){try{returnproxyaddr(req,trust)asstring}catch{// fall back to remote address on any error}}}returnremoteAddressasstring}
The injection endpoints and logging now use getClientIp with the trusted proxies configuration. Confirm that all relevant endpoints and logging statements have been updated and that the function is called with the correct parameters, especially in cases where config.server.trustedProxies may be undefined.
requestIP=getClientIp(req,config.server.trustedProxies||[])||'cant-get-ip'}letserviePointSpenders: Map<string,number>=debugServicePointSpendersByType.get(key)if(!serviePointSpenders){serviePointSpenders=newMap()debugServicePointSpendersByType.set(key,serviePointSpenders)}if(serviePointSpenders.has(requestIP)===false){serviePointSpenders.set(requestIP,points)}else{constcurrentPoints=serviePointSpenders.get(requestIP)serviePointSpenders.set(requestIP,currentPoints+points)}debugTotalServicePointRequests+=points//upate debugServiePointByTypeif(debugServicePointsByType.has(key)===false){debugServicePointsByType.set(key,points)}else{constcurrentPoints=debugServicePointsByType.get(key)debugServicePointsByType.set(key,currentPoints+points)}}//is the new operation too expensive?if(totalPoints+points>maxAllowedPoints){nestedCountersInstance.countEvent('shardeum-service-points','fail: not enough points available to spend')returnfalse}//Add new entry to arrayconstnewEntry={ points,ts: nowTs}servicePointSpendHistory.unshift(newEntry)nestedCountersInstance.countEvent('shardeum-service-points','pass: points available to spend')returntrue}functionpruneOldBlocks(): void{/* eslint-disable security/detect-object-injection */constmaxOldBlocksCount=ShardeumFlags.maxNumberOfOldBlocks||256if(latestBlock>maxOldBlocksCount){for(leti=10;i>0;i--){constblock=latestBlock-maxOldBlocksCount-iif(blocks[block]){try{constblockHash=readableBlocks[block].hashdeleteblocks[block]deleteblocksByHash[blockHash]deletereadableBlocks[block]/* prettier-ignore */if(ShardeumFlags.VerboseLogs)console.log('Lengths of blocks after pruning',Object.keys(blocksByHash).length,Object.keys(readableBlocks).length)}catch(e){/* prettier-ignore */if(logFlags.error)console.log('Error: pruneOldBlocks',e)}}}}/* eslint-enable security/detect-object-injection */}functionconvertToReadableBlock(block: Block): ShardeumBlockOverride{
The reason will be displayed to describe this comment to others. Learn more.
Suggestion: The function may return non-string values (such as undefined or null) in some cases, which could cause downstream errors. Ensure the return value is always a string or explicitly null. [possible issue, importance: 7]
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
Summary
trustedProxiesconfig option with env var overridegetClientIpto only honor X-Forwarded-For from trusted sourcesTesting
npm run compilenpm testPR Type
Enhancement, Documentation
Description
Add trusted proxy IP support via config and env variable
Implement secure
getClientIpto validate proxy headersUpdate endpoints and logging to use trusted proxy logic
Document trusted proxy configuration in README and setup guide
Changes walkthrough 📝
index.ts
Add trustedProxies config and env variable supportsrc/config/index.ts
trustedProxiesoption to server config interfacetrustedProxiesas empty array in default configTRUSTED_PROXIESenv variable to override configindex.ts
Use secure client IP extraction with trusted proxiessrc/index.ts
unsafeGetClientIpwith newgetClientIpusing trusted proxiesrequests.ts
Implement secure getClientIp with trusted proxy validationsrc/utils/requests.ts
getClientIpfunction validating trusted proxiesproxy-addrfor secure proxy header parsingREADME.md
Document trusted proxy configuration in READMEREADME.md
TRUSTED_PROXIESenv variable and config optionconfig.json
Add trustedProxies to example config.jsonconfig.json
trustedProxiesarray to example server configlocal-environment-setup.md
Document trusted proxy setup in environment guidelocal-environment-setup.md