Commit 327bdf3f authored by Graham Leggett's avatar Graham Leggett
Browse files

Introduce a per connection "peer_ip" and a per request "client_ip" to

distinguish between the raw IP address of the connection and the effective
IP address of the request.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1206291 13f79535-47bb-0310-9956-ffa450edef68
parent 27b6feec
Loading
Loading
Loading
Loading
+4 −4
Changes for include/httpd.h: 4 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -1007,8 +1007,8 @@ struct request_rec {
    /** remote address information from conn_rec, can be overridden if
     * necessary by a module.
     */
    apr_sockaddr_t *remote_addr;
    char *remote_ip;
    apr_sockaddr_t *client_addr;
    char *client_ip;
};

/**
@@ -1052,10 +1052,10 @@ struct conn_rec {
    /** local address */
    apr_sockaddr_t *local_addr;
    /** remote address */
    apr_sockaddr_t *remote_addr;
    apr_sockaddr_t *peer_addr;

    /** Client's IP address */
    char *remote_ip;
    char *peer_ip;
    /** Client's DNS name, if known.  NULL if DNS hasn't been checked,
     *  "" if it has and no address was found.  N.B. Only access this though
     * get_remote_host() */
+1 −1
Changes for modules/aaa/mod_access_compat.c: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -271,7 +271,7 @@ static int find_allowdeny(request_rec *r, apr_array_header_t *a, int method)
            return 1;

        case T_IP:
            if (apr_ipsubnet_test(ap[i].x.ip, r->remote_addr)) {
            if (apr_ipsubnet_test(ap[i].x.ip, r->client_addr)) {
                return 1;
            }
            break;
+4 −4
Changes for modules/aaa/mod_authz_host.c: 4 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -153,7 +153,7 @@ static authz_status ip_check_authorization(request_rec *r,
    apr_ipsubnet_t **ip = (apr_ipsubnet_t **)parsed_require_line;

    while (*ip) {
        if (apr_ipsubnet_test(*ip, r->remote_addr))
        if (apr_ipsubnet_test(*ip, r->client_addr))
            return AUTHZ_GRANTED;
        ip++;
    }
@@ -201,10 +201,10 @@ static authz_status local_check_authorization(request_rec *r,
                                              const void *parsed_require_line)
{
     if (   apr_sockaddr_equal(r->connection->local_addr,
                               r->remote_addr)
         || apr_ipsubnet_test(localhost_v4, r->remote_addr)
                               r->client_addr)
         || apr_ipsubnet_test(localhost_v4, r->client_addr)
#if APR_HAVE_IPV6
         || apr_ipsubnet_test(localhost_v6, r->remote_addr)
         || apr_ipsubnet_test(localhost_v6, r->client_addr)
#endif
        )
     {
+1 −1
Changes for modules/arch/netware/mod_nw_ssl.c: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -1001,7 +1001,7 @@ char *ssl_var_lookup(apr_pool_t *p, server_rec *s, conn_rec *c, request_rec *r,
            else if (strcEQ(var, "REQUEST_FILENAME"))
                result = r->filename;
            else if (strcEQ(var, "REMOTE_ADDR"))
                result = r->remote_ip;
                result = r->client_ip;
            else if (strcEQ(var, "REMOTE_HOST"))
                result = ap_get_remote_host(r->connection, r->per_dir_config,
                                            REMOTE_NAME, NULL);
+3 −3
Changes for modules/echo/mod_echo.c: 3 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -154,7 +154,7 @@ static int process_echo_connection(conn_rec *c)
            if (!APR_STATUS_IS_EOF(rv) && ! APR_STATUS_IS_TIMEUP(rv))
                ap_log_error(APLOG_MARK, APLOG_INFO, rv, c->base_server,
                             "ProtocolEcho: Failure reading from %s",
                             c->remote_ip);
                             c->peer_ip);
            break;
        }

@@ -163,7 +163,7 @@ static int process_echo_connection(conn_rec *c)
            apr_brigade_cleanup(bb);
            ap_log_error(APLOG_MARK, APLOG_INFO, rv, c->base_server,
                         "ProtocolEcho: Error - read empty brigade from %s!",
                         c->remote_ip);
                         c->peer_ip);
            break;
        }

@@ -181,7 +181,7 @@ static int process_echo_connection(conn_rec *c)
        if (rv != APR_SUCCESS) {
            ap_log_error(APLOG_MARK, APLOG_INFO, rv, c->base_server,
                         "ProtocolEcho: Failure writing to %s",
                         c->remote_ip);
                         c->peer_ip);
            break;
        }
        apr_brigade_cleanup(bb);
Loading