Skip to content

Document security considerations for forwarded headers in cloud deployments #49507

@bclozel

Description

@bclozel

We should highlight that while "forwarded headers" support is enabled automatically for cloud platforms, we generally assume that apps are behind trusted HTTP proxies. If this is not the case, app developers should disable this feature if they choose to expose the application to direct Internet traffic.

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions