Why can't I spoof my ip address and trick the Marklogic function 'xdmp:get-request-client-address' to think I'm somewhere else in the world?

Viewed 53

I've tried using an x-forwarded-for header with IP addresses from Mexico, London, etc... I've used the google sensor tool to change my IP but Marklogic somehow sees through those techniques when I log the results of this function xdmp:get-request-client-address.

1 Answers

Because xdmp:get-request-client-address() returns

the internet address of the client from which the HTTP server request is issued

If you want the value of the x-forwarded-for header, then use xdmp:get-request-header(). You can use the request client address as a default value in case that header is not found:

xdmp:get-request-header("x-forwarded-for", xdmp:get-request-client-address())
Related