incubator-callback-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Matti Paksula (JIRA)" <>
Subject [jira] [Commented] (CB-1494) Supports running server behind a proxy, such as Heroku Cedar
Date Tue, 18 Sep 2012 12:06:07 GMT


Matti Paksula commented on CB-1494:

_> Whether or not you submit a CCLA, YOU WILL ALSO NEED TO SUBMIT AN ICLA._

Yes, both ICLA (5x from all of us at AppGyver) and CCLA are being submitted to ASF ~tomorrow.

_> Also note that it wasn't immediately clear to me that the XFF header can actually be
a set of IP addresses, not just one._

You are right, I did not look into XFF in detail. I've updated the pull request to take the
last ip or host from the string (the last is set by the proxy and I verified that it actually
works in Heroku):

$ curl --header "X-Forwarded-For:" "",
... so actual host/ip gets set even if spoofing is attempted. So there should not be any security

I've updated the pull-request with a new commit to support a set of addresses.

Testable pre-built NPM of that is here:

We could also add an option to turn support for XFF on, but I think it should be the default
behaviour and used if set (like you would expect when you deploy Weinre to Heroku or other
proxied environment)

_> Although, I'm wondering about places we dump the ip address into HTML to being with
- like in the remote panel. Can someone check that?_

Yes it gets dumped, but should this be fixed?

_> Should we add something to the doc? I'm thinking a quick mention that we support XFF
should be good enough._

Yes, adding a bullet in MultiUser.html notes section?

(are there any plans to write some tests for weinre?)
(what about the state of documentation?)

> Supports running server behind a proxy, such as Heroku Cedar
> ------------------------------------------------------------
>                 Key: CB-1494
>                 URL:
>             Project: Apache Cordova
>          Issue Type: New Feature
>          Components: weinre
>            Reporter: Patrick Mueller
>            Assignee: Patrick Mueller
> created for

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see:

View raw message