[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"$fkhp3a52bhal4":3,"$f2oq8zkjpqryy5":21},{"content":4,"package":5,"version":20},"# Resolve Forwarded Client Address Middleware\n\nThe `BabDev\\WebSocket\\Server\\Http\\Middleware\\ResolveForwardedClientAddress` class is a [server middleware](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware) which is used when the websocket server is behind a reverse proxy (such as nginx or a load balancer).\n\nBehind a proxy, every connection to the server comes from the proxy, so the connection's `remote_address` attribute is the proxy's IP address instead of the client's. When a connection comes from a trusted proxy, this middleware reads the client's IP address from the forwarding headers set by the proxy and replaces the `remote_address` attribute with it, keeping the proxy's IP address in the `proxy_address` attribute. Middleware which run after this middleware, such as the [`BabDev\\WebSocket\\Server\\Http\\Middleware\\RejectBlockedIpAddress`](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Freject-blocked-ip-address) middleware, then use the client's IP address.\n\nThe middleware follows the same conventions as the trusted proxy support in [Symfony's `Request` class](https:\u002F\u002Fsymfony.com\u002Fdoc\u002Fcurrent\u002Fdeployment\u002Fproxies.html), and uses the same constants to configure which headers are trusted.\n\n## Configuring Trusted Proxies\n\nThe middleware requires the list of trusted proxies and, optionally, a bit field of the headers to trust (defaults to `X-Forwarded-For`):\n\n```php\n\u003C?php declare(strict_types=1);\n\nuse BabDev\\WebSocket\\Server\\Http\\Middleware\\ResolveForwardedClientAddress;\nuse Symfony\\Component\\HttpFoundation\\Request;\n\n$middleware = new ResolveForwardedClientAddress(\n    $decoratedMiddleware,\n    ['192.0.2.1', '10.0.0.0\u002F8'],\n    Request::HEADER_X_FORWARDED_FOR | Request::HEADER_FORWARDED,\n);\n```\n\nThe list of trusted proxies supports single IP addresses and subnet ranges, as well as two special values:\n\n- `PRIVATE_SUBNETS` - trusts all private network ranges (see `Symfony\\Component\\HttpFoundation\\IpUtils::PRIVATE_SUBNETS`)\n- `REMOTE_ADDR` - trusts every connection; only use this when the server can only be reached through the proxy\n\nOnly the `Request::HEADER_X_FORWARDED_FOR` (the `X-Forwarded-For` header) and `Request::HEADER_FORWARDED` (the [RFC 7239](https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc7239) `Forwarded` header) values are used by this middleware, any other headers in the bit field are ignored.\n\nOnly trust the headers your proxy sets. A proxy which sets one of these headers usually passes the other through from the client unchanged, so trusting a header your proxy does not set allows clients to send any IP address.\n\n## Resolving the Client Address\n\nThe forwarding headers contain the list of addresses the request passed through. The client address is the last address in the list which is not a trusted proxy, so a client cannot spoof its address by sending its own forwarding header. If every address is a trusted proxy, the first address is used. Invalid addresses are ignored, and the client address is normalized in the same way as the `remote_address` attribute (see the [connection documentation](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fconnection#remote-address-normalization)).\n\nIf both headers are trusted and they resolve to different client addresses, the connection is closed with a `400 Bad Request` response and a `BabDev\\WebSocket\\Server\\Http\\Exception\\ConflictingForwardedHeaders` exception is thrown.\n\n## Position in Middleware Stack\n\nThis middleware requires the HTTP request, so it must be decorated by the `BabDev\\WebSocket\\Server\\Http\\Middleware\\ParseHttpRequest` middleware (see the [message flow](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Farchitecture#message-flow) section from the architecture documentation to see the recommended stack with all optional middleware).\n\nIt is recommended that this middleware decorates the `BabDev\\WebSocket\\Server\\Http\\Middleware\\RejectBlockedIpAddress` middleware, so blocked addresses are checked against the client's IP address.\n\nWhen using the `BabDev\\WebSocket\\Server\\Application` class, this middleware is registered with the `withTrustedProxies()` method.\n",{"name":6,"slug":7,"description":8,"github":9,"packagistName":12,"packageType":13,"hasDocumentation":14,"supported":14,"visible":14,"versions":15},"WebSocket Server","websocket-server","PHP library to create a WebSocket server",{"owner":10,"repo":11},"BabDev","WebSocket-Server","babdev\u002Fwebsocket-server","php-package",true,[16],{"version":17,"gitBranch":18,"released":19},"1.x","0.1",false,{"version":17,"gitBranch":18,"released":19},{"content":22,"package":23,"version":27},"- [Introduction](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fintro)\n- [Installation & Setup](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Finstallation)\n- [Architecture](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Farchitecture)\n- [Connection](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fconnection)\n- [Error URI Resolver](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Ferror-uri-resolver)\n- [Message Handler](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmessage-handler)\n- [Message Handler Resolver](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmessage-handler-resolver)\n- [Middleware](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware)\n  - [Dispatch Message To Handler](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Fdispatch-message-to-handler)\n  - [Establish WebSocket Connection](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Festablish-websocket-connection)\n  - [Initialize Session](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Finitialize-session)\n  - [Parse HTTP Request](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Fparse-http-request)\n  - [Parse WAMP Message](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Fparse-wamp-message)\n  - [Reject Blocked IP Address](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Freject-blocked-ip-address)\n  - [Resolve Forwarded Client Address](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Fresolve-forwarded-client-address)\n  - [Restrict to Allowed Origins](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Frestrict-to-allowed-origins)\n  - [Update Topic Subscriptions](\u002Fopen-source\u002Fpackages\u002Fwebsocket-server\u002Fdocs\u002F1.x\u002Fmiddleware\u002Fupdate-topic-subscriptions)\n",{"name":6,"slug":7,"description":8,"github":24,"packagistName":12,"packageType":13,"hasDocumentation":14,"supported":14,"visible":14,"versions":25},{"owner":10,"repo":11},[26],{"version":17,"gitBranch":18,"released":19},{"version":17,"gitBranch":18,"released":19},1791293200056]