Uh oh!
There was an error while loading. Please reload this page.
Fix/swoole trusted proxies per request - #195
Open
outcomer wants to merge 5 commits into
Open
Conversation
Hardcoded 4096-byte ob_start() threshold starves SSE — small, time-spaced writes never reach the client until the buffer fills or the response ends. Adds a `streamed_response_chunk_size` ServerFactory option (default 4096, unchanged behavior), grouped into a BridgeOptions value object.
Symfony's Kernel resolves trusted_proxies (including the REMOTE_ADDR sentinel) once at boot(), which under Swoole's long-lived workers means every request after the first keeps whatever REMOTE_ADDR was seen at that one moment — silently breaking proxy trust, and with it X-Forwarded-Proto-based scheme detection, for the rest of the worker's life. SymfonyRunner::handle() now re-applies TRUSTED_PROXIES/TRUSTED_HEADERS from the environment before every request, using that request's own REMOTE_ADDR for the sentinel.
outcomer
marked this pull request as ready for review
August 17, 2026 16:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Re-resolve trusted proxies per request in Swoole runner
Symfony's Kernel resolves trusted_proxies (including the REMOTE_ADDR
sentinel) once at boot(), which under Swoole's long-lived workers
means every request after the first keeps whatever REMOTE_ADDR was
seen at that one moment — silently breaking proxy trust, and with it
X-Forwarded-Proto-based scheme detection, for the rest of the
worker's life.
SymfonyRunner::handle() now re-applies TRUSTED_PROXIES/TRUSTED_HEADERS
from the environment before every request, using that request's own
REMOTE_ADDR for the sentinel.