[IMP] developer/reference/cli: --proxy-mode - #6729
Julien00859 wants to merge 1 commit into
Conversation
f91f30b to
15885db
Compare
|
Hello @odoo/doc-review I've met with Olivier and he agrees with the changes. We cn move on with the editorial review and merging it :) |
AntoineVDV
left a comment
There was a problem hiding this comment.
Kudos for targeting 15.0 👍
@robodoo delegate+
15885db to
055adae
Compare
Many customers struggle with their web server configuration, notably regarding the `--proxy-mode` option and the way `X-Forwarded-*` HTTP request headers are interpreted within Odoo. The `--proxy-mode` section has been updated to cover the most common misunderstandings and to give guidances on how to setup a web server. Odoo always only takes the last entry of the `X-Forwarded-*` request header because there are situations where it is not possible to determine which last n-th entry to use. Employees might access their odoo database via the internal network: connecting directly to nginx, while customers might access the database via an additional proxy such as cloudflare. The real IP of employees would be the last inside the `X-Forwarded-For` chain, while the real IP of customers would be the *second* last entry inside the chain. It would be incorrect to always take the same nth last entry inside the chain. The cloudflare's own IP address must be discarded from the chain. Web servers usually feature a way to ignore trusted IP from the chain, a way so that the real IP of the user is always the last entry inside the chain. Odoo relies on such feature to be active and configured. Prior discussions about `X-Forwarded-For`: * odoo/odoo#104947 * odoo/odoo#118629 * odoo/odoo#139536 All `X-Forwarded-*` headers are ignored in case the `X-Forwarded-Host` header is missing (even with `--proxy-mode`). System admin might be tempted to not set this header and to set `Host` instead, this is broken as this a user-agent would be able to spoof `X-Forwarded-Host` and Odoo would use that instead of the correct `Host`. Prior discussions about `X-Forwarded-Host`: * odoo/odoo#63277 * odoo/odoo#70117
055adae to
8ddc147
Compare
|
@fw-bot up to master |
|
Forward-porting to 'master'. |
| support`_. | ||
|
|
||
| It ignores all ``X-Forwarded-*`` headers in case ``X-Forwarded-Host`` is | ||
| missing from the request. |
There was a problem hiding this comment.
I think this language should be stronger. Something like "A properly configured proxy upstream must provide X-Forwarded-Host or --proxy-mode is ignored.
There was a problem hiding this comment.
Ah shit I only see your message now and the PR as been merged. I don't think using a stronger language is actually needed, the piece of information was missing and people had some expectations, now that the info is there I think they'll configure their proxies accordingly.
There was a problem hiding this comment.
We'll see, in case we continue to get messages on the matter we can still open another PR and change the wording :)
Many customers struggle with their web server configuration, notably regarding the `--proxy-mode` option and the way `X-Forwarded-*` HTTP request headers are interpreted within Odoo. The `--proxy-mode` section has been updated to cover the most common misunderstandings and to give guidances on how to setup a web server. Odoo always only takes the last entry of the `X-Forwarded-*` request header because there are situations where it is not possible to determine which last n-th entry to use. Employees might access their odoo database via the internal network: connecting directly to nginx, while customers might access the database via an additional proxy such as cloudflare. The real IP of employees would be the last inside the `X-Forwarded-For` chain, while the real IP of customers would be the *second* last entry inside the chain. It would be incorrect to always take the same nth last entry inside the chain. The cloudflare's own IP address must be discarded from the chain. Web servers usually feature a way to ignore trusted IP from the chain, a way so that the real IP of the user is always the last entry inside the chain. Odoo relies on such feature to be active and configured. Prior discussions about `X-Forwarded-For`: * odoo/odoo#104947 * odoo/odoo#118629 * odoo/odoo#139536 All `X-Forwarded-*` headers are ignored in case the `X-Forwarded-Host` header is missing (even with `--proxy-mode`). System admin might be tempted to not set this header and to set `Host` instead, this is broken as this a user-agent would be able to spoof `X-Forwarded-Host` and Odoo would use that instead of the correct `Host`. Prior discussions about `X-Forwarded-Host`: * odoo/odoo#63277 * odoo/odoo#70117 closes #6729 Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Many customers struggle with their web server configuration, notably regarding the
--proxy-modeoption and the wayX-Forwarded-*HTTP request headers are interpreted within Odoo.The
--proxy-modesection has been updated to cover the most common misunderstandings and to give guidances on how to setup a web server.Odoo always only takes the last entry of the
X-Forwarded-*request header because there are situations where it is not possible to determine which last n-th entry to use. Employees might access their odoo database via the internal network: connecting directly to nginx, while customers might access the database via an additional proxy such as cloudflare. The real IP of employees would be the last inside theX-Forwarded-Forchain, while the real IP of customers would be the second last entry inside the chain. It would be incorrect to always take the same nth last entry inside the chain. The cloudflare's own IP address must be discarded from the chain. Web servers usually feature a way to ignore trusted IP from the chain, a way so that the real IP of the user is always the last entry inside the chain. Odoo relies on such feature to be active and configured.Prior discussions about
X-Forwarded-For:proxy_mode = Trueno honoured at all odoo#104947All
X-Forwarded-*headers are ignored in case theX-Forwarded-Hostheader is missing (even with--proxy-mode). System admin might be tempted to not set this header and to setHostinstead, this is broken as this a user-agent would be able to spoofX-Forwarded-Hostand Odoo would use that instead of the correctHost.Prior discussions about
X-Forwarded-Host: