Details
-
Bug
-
Resolution: Unresolved
-
Neutral
-
None
-
5.4.7, 5.5
-
Windows Server 2012 R2, Oracle Linux 7
Description
Incorrect remote client IP address captured in audit log when Magnolia CMS hosted behind proxy server or reverse proxy or security gateway or firewall.
Magnolia CMS should not rely on request.getRemoteAddr() to get client remote address. X-Forwarded-For header should be taken into consideration or configuration to be provided to customise the audit log to include extra information from client request.
Checklists
Acceptance criteria