{"id":15345482,"url":"https://github.com/akrabat/ip-address-middleware","last_synced_at":"2025-05-15T03:05:28.618Z","repository":{"id":1904403,"uuid":"45299829","full_name":"akrabat/ip-address-middleware","owner":"akrabat","description":"PSR-7 Middleware that determines the client IP address and stores it as a PSR-7 ServerRequest attribute","archived":false,"fork":false,"pushed_at":"2025-01-18T13:33:22.000Z","size":116,"stargazers_count":168,"open_issues_count":0,"forks_count":38,"subscribers_count":11,"default_branch":"main","last_synced_at":"2025-04-21T03:50:23.315Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/akrabat.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2015-10-31T11:55:20.000Z","updated_at":"2025-01-18T13:31:15.000Z","dependencies_parsed_at":"2024-06-09T14:36:33.510Z","dependency_job_id":"c82d9251-0364-424a-a1e8-6f5d8d348c38","html_url":"https://github.com/akrabat/ip-address-middleware","commit_stats":{"total_commits":87,"total_committers":16,"mean_commits":5.4375,"dds":0.5517241379310345,"last_synced_commit":"00a053e8513620f55a827e837d1468ec8b1264db"},"previous_names":[],"tags_count":17,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/akrabat%2Fip-address-middleware","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/akrabat%2Fip-address-middleware/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/akrabat%2Fip-address-middleware/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/akrabat%2Fip-address-middleware/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/akrabat","download_url":"https://codeload.github.com/akrabat/ip-address-middleware/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254264765,"owners_count":22041793,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-10-01T11:13:36.103Z","updated_at":"2025-05-15T03:05:28.584Z","avatar_url":"https://github.com/akrabat.png","language":"PHP","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Client IP address middleware\n\nPSR-15 Middleware that determines the client IP address and stores it as an `ServerRequest` attribute called `ip_address`. It optionally checks various common proxy headers and then falls back to `$_SERVER['REMOTE_ADDR']`.\n\n## Installation\n\nInstall via Composer:\n\n```bash\ncomposer require akrabat/ip-address-middleware\n``` \n\n## Configuration\n\nThe constructor takes 5 parameters which can be used to configure this middleware.\n\n**Check proxy headers**\n\nThe proxy headers are only checked if the first parameter to the constructor is set to `true`. If it is set to `false`, then only `$_SERVER['REMOTE_ADDR']` is used.\n\n**Trusted Proxies**\n\nIf you enable checking of the proxy headers (first parameter is `true`), you have to provide an array as the second parameter. This is the list of IP addresses (supporting wildcards) of your proxy servers. If the array is empty, the proxy headers will always be used and the selection is based on the hop count (parameter 5). \n\nIf the array is not empty, it must contain strings with IP addresses (wildcard `*` is allowed in any given part) or networks in CIDR-notation. One of them must match the `$_SERVER['REMOTE_ADDR']` variable in order to allow evaluating the proxy headers - otherwise the `REMOTE_ADDR` itself is returned. This list is not ordered and there is no requirement that any given proxy header includes all the listed proxies.\n\n**Attribute name**\n\nBy default, the name of the attribute is '`ip_address`'. This can be changed by the third constructor parameter.\n\n**Headers to inspect**\n\nBy default, this middleware checks the 'Forwarded', 'X-Forwarded-For', 'X-Forwarded', 'X-Cluster-Client-Ip' and 'Client-Ip' headers. You can replace this list with your own using the fourth constructor parameter.\n\nIf you use the _nginx_, [set_real_ip_from][nginx] directive, then you should probably set this to:\n\n    $headersToInspect = [\n        'X-Real-IP',\n        'Forwarded',\n        'X-Forwarded-For',\n        'X-Forwarded',\n        'X-Cluster-Client-Ip',\n        'Client-Ip',\n    ];\n\nIf you use _CloudFlare_, then according to the [documentation][cloudflare] you should probably set this to:\n\n    $headersToInspect = [\n        'CF-Connecting-IP',\n        'True-Client-IP',\n        'Forwarded',\n        'X-Forwarded-For',\n        'X-Forwarded',\n        'X-Cluster-Client-Ip',\n        'Client-Ip',\n    ];\n\n[nginx]: http://nginx.org/en/docs/http/ngx_http_realip_module.html\n[cloudflare]: https://support.cloudflare.com/hc/en-us/articles/200170986-How-does-Cloudflare-handle-HTTP-Request-headers-\n\n**hop count**\n\nSet this to the number of known proxies between ingress and the application. This is used to determine the number of\nproxies to check in the `X-Forwarded-For` header, and is generally used when the IP addresses of the proxies cannot\nbe reliably determined. The default is 0.\n\n## Security considerations\n\nA malicious client may send any header to your proxy, including any proxy headers, containing any IP address. If your proxy simply adds another IP address to the header, an attacker can send a fake IP. Make sure to setup your proxy in a way that removes any sent (and possibly faked) headers from the original request and replaces them with correct values (i.e. the currently used `REMOTE_ADDR` on the proxy server).\n\nThis library cannot by design ensure you get correct and trustworthy results if your network environment isn't setup properly.\n\n## Installation\n\n`composer require akrabat/ip-address-middleware`\n\nIn Mezzio, copy `Mezzio/config/ip_address.global.php.dist` into your Mezzio Application `config/autoload` directory as `ip_address.global.php`\n\n## Usage\n\nIn Slim:\n\n```php\n$checkProxyHeaders = true; // Note: Never trust the IP address for security processes!\n$trustedProxies = ['10.0.0.1', '10.0.0.2']; // Note: Never trust the IP address for security processes!\n$app-\u003eadd(new RKA\\Middleware\\IpAddress($checkProxyHeaders, $trustedProxies));\n\n$app-\u003eget('/', function ($request, $response, $args) {\n    $ipAddress = $request-\u003egetAttribute('ip_address');\n\n    return $response;\n});\n```\n\nIn Laminas or Mezzio, add to your `pipeline.php` config at the correct stage, usually just before the `DispatchMiddleware`:\n```php\n# config/pipeline.php\n# using default config\n$app-\u003eadd(RKA\\Middleware\\IpAddress::class);\n```\nIf required, update your `.env` file with the environmental variables found in `/config/autoload/ip_address.global.php`.\n\n## Testing\n\n* Code style: `$ vendor/bin/phpcs`\n* Fix style: `$ vendor/bin/phpcbf`\n* Unit tests: `$ vendor/bin/phpunit`\n* Code coverage: `$ vendor/bin/phpunit --coverage-html ./build`\n\nYou can also use Composer scripts:\n\n* Check both: `$ composer check`\n* Code style: `$ composer cs`\n* Fix style: `$ composer cs-fix`\n* Unit tests: `$ composer test`\n\n\n[Master]: https://travis-ci.org/akrabat/ip-address-middleware\n[Master image]: https://secure.travis-ci.org/akrabat/ip-address-middleware.svg?branch=master\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fakrabat%2Fip-address-middleware","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fakrabat%2Fip-address-middleware","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fakrabat%2Fip-address-middleware/lists"}