Authorize requests with hasIpAddress expression but using IP forwarded from reverse proxy?

Viewed 239

I'm using SpringSecurity with SpringBoot and trying to limit access from specific IP addresses. I'm using standard http.authorizeRequests().antMatchers("/api/**").access("hasIpAddress('xxx.xxx.xxx.xxx/16')"); and it works correctly when accessing server directly. But production system is however behing haproxy. We are sending X-Forwarded-For info using haproxy to our app and added these two lines info application.properties

server.use-forward-headers=true
server.tomcat.remote-ip-header=X-Forwarded-For

... but still can't access the url. Any idea whats missing or if something must be done differently for checking forwarded remote ip?

0 Answers
Related