Skip to main content

RealIpPlugin

Struct RealIpPlugin 

Source
pub struct RealIpPlugin {
    source: String,
    trusted_addresses: Option<Vec<IpNet>>,
    recursive: bool,
}
Expand description

Replaces context.request.remote_addr with the address carried by a configured variable, guarded by a trusted-proxy allowlist.

source: http_x_forwarded_for gets APISIX’s special X-Forwarded-For handling (last header value, comma-splitting, optional recursive walk); any other source is resolved through the standard variable resolver (crate::vars::resolve), e.g. http_x_real_ip or arg_realip.

Fields§

§source: String

Variable name the real address is read from.

§trusted_addresses: Option<Vec<IpNet>>

Only rewrite when the direct peer matches one of these networks. None means “always rewrite” (mirrors APISIX, where the field is optional).

§recursive: bool

X-Forwarded-For only: walk the list right-to-left, skipping trusted hops, instead of taking the last (rightmost) entry.

Implementations§

Source§

impl RealIpPlugin

Source

pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>

Builds the plugin from node config.

Accepted keys:

  • source (string, required): variable holding the real address, e.g. http_x_real_ip or http_x_forwarded_for (the latter gets comma-list handling). See crate::vars::resolve for the variable namespace.
  • trusted_addresses (array of IPs/CIDRs, optional): the rewrite only applies when the direct peer address matches one of these. When omitted the rewrite always applies. An empty array or an invalid IP/CIDR is a config error.
  • recursive (bool, default false): for http_x_forwarded_for with trusted_addresses, walk the list from the rightmost entry, skip trusted hops, and take the first untrusted address (falling back to the leftmost entry when every hop is trusted). When false, the last (rightmost) entry is used.
type: real-ip
config:
  source: http_x_forwarded_for
  trusted_addresses: ["127.0.0.0/24", "10.0.0.0/8"]
  recursive: true
Source

fn is_trusted(&self, ip: IpAddr) -> bool

True when ip is inside one of the trusted networks. Always false when no trusted_addresses are configured (callers guard on that).

Source

fn get_addr(&self, ctx: &Context) -> Option<String>

Extracts the candidate real address from the configured source, mirroring APISIX’s get_addr.

Trait Implementations§

Source§

impl Plugin for RealIpPlugin

Source§

fn plugin_type(&self) -> &str

Unique identifier for the plugin type (e.g., “proxy-rewrite”, “upstream”).
Source§

fn execute<'life0, 'life1, 'async_trait>( &'life0 self, ctx: Context, _named_inputs: &'life1 HashMap<String, Value>, ) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Executes the plugin logic against the request/response context. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<T> MaybeSend for T