Caddyfile: reverse_proxy header_up setter is redundant

(#821) Bug Fixed self-hosting

Documentation defect

Caddy automatically sets XFF, XFP and XFH headers, as long as the requesting proxy IP is seen as trusted. You can do that by adding proxy's CIDR in trusted_proxies global directive. Since it is already enforced here and set to strict with a way to configure it via .env, these header_up setters should be removed from all reverse_proxy directives as they're pretty much redundant and Caddy will still strip this header if it comes from a CIDR it does not trust anyway. Caddy default behavior also grabs {client_ip} for X-Forwarded-For header. Caddy is pretty similar to Traefik in this case! See: https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#defaults and https://caddy.community/t/caddy-reverse-proxy-x-forwarded-for-headers/26682/2

Location

https://docs.fluxer.app/operator/reverse-proxy/#caddy

Proposed wording

Can just re-use same wording that Traefik has - "Caddy forwards WebSocket upgrades natively, and by default it strips inbound X-Forwarded-* headers from untrusted clients and writes its own."

2 comments

Sign in with Fluxer to comment and vote.