Talk about spring cloud gateway’s XForwardedHeadersFilter

  springcloud

Order

This paper mainly studies the XForwardedHeadersFilter of spring cloud gateway.

GatewayAutoConfiguration

spring-cloud-gateway-core-2.0.0.RC1-sources.jar! /org/springframework/cloud/gateway/config/GatewayAutoConfiguration.java

@Configuration
@ConditionalOnProperty(name = "spring.cloud.gateway.enabled", matchIfMissing = true)
@EnableConfigurationProperties
@AutoConfigureBefore(HttpHandlerAutoConfiguration.class)
@AutoConfigureAfter({GatewayLoadBalancerClientAutoConfiguration.class, GatewayClassPathWarningAutoConfiguration.class})
@ConditionalOnClass(DispatcherHandler.class)
public class GatewayAutoConfiguration {
    //......
    @Bean
    @ConditionalOnProperty(name = "spring.cloud.gateway.x-forwarded.enabled", matchIfMissing = true)
    public XForwardedHeadersFilter xForwardedHeadersFilter() {
        return new XForwardedHeadersFilter();
    }
    //......
}

XForwardedHeadersFilter is registered by default

XForwardedHeadersFilter

spring-cloud-gateway-core-2.0.0.RC1-sources.jar! /org/springframework/cloud/gateway/filter/headers/XForwardedHeadersFilter.java

@ConfigurationProperties("spring.cloud.gateway.x-forwarded")
public class XForwardedHeadersFilter implements HttpHeadersFilter, Ordered {
    //......
    @Override
    public HttpHeaders filter(HttpHeaders input, ServerWebExchange exchange) {
        ServerHttpRequest request = exchange.getRequest();
        HttpHeaders original = input;
        HttpHeaders updated = new HttpHeaders();

        original.entrySet().stream()
                .forEach(entry -> updated.addAll(entry.getKey(), entry.getValue()));

        if (isForEnabled()) {
            String remoteAddr = request.getRemoteAddress().getAddress().getHostAddress();
            List<String> xforwarded = original.get(X_FORWARDED_FOR_HEADER);
            // prevent duplicates
            if (remoteAddr != null &&
                    (xforwarded == null || !xforwarded.contains(remoteAddr))) {
                write(updated, X_FORWARDED_FOR_HEADER, remoteAddr, isForAppend());
            }
        }

        String proto = request.getURI().getScheme();
        if (isProtoEnabled()) {
            write(updated, X_FORWARDED_PROTO_HEADER, proto, isProtoAppend());
        }

        if (isPortEnabled()) {
            String port = String.valueOf(request.getURI().getPort());
            if (request.getURI().getPort() < 0) {
                port = String.valueOf(getDefaultPort(proto));
            }
            write(updated, X_FORWARDED_PORT_HEADER, port, isPortAppend());
        }

        if (isHostEnabled()) {
            String host = toHostHeader(request);
            write(updated, X_FORWARDED_HOST_HEADER, host, isHostAppend());
        }

        return updated;
    }

    //......
}
  • If spring.cloud.gateway.x-forwarded.for-enabled is true, X-Forwarded-For is written.
  • If spring.cloud.gateway.x-forwarded.proto-enabled is true, X-Forwarded-Proto is written.
  • If spring.cloud.gateway.x-forwarded.port-enabled is true, X-Forwarded-Port is written.
  • If spring.cloud.gateway.x-forwarded.host-enabled is true, X-Forwarded-Host is written.

Each enable attribute has an append attribute that determines whether to add or append

    private void write(HttpHeaders headers, String name, String value, boolean append) {
        if (append) {
            headers.add(name, value);
            // these headers should be treated as a single comma separated header
            List<String> values = headers.get(name);
            String delimitedValue = StringUtils.collectionToCommaDelimitedString(values);
            headers.set(name, delimitedValue);
        } else {
            headers.set(name, value);
        }
    }

If it is append, commas are written to headers separately; if not, set operation is taken.

Configuration

    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.enabled",
      "description": "If the XForwardedHeadersFilter is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.for-append",
      "description": "If appending X-Forwarded-For as a list is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.for-enabled",
      "description": "If X-Forwarded-For is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.host-append",
      "description": "If appending X-Forwarded-Host as a list is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.host-enabled",
      "description": "If X-Forwarded-Host is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": 0,
      "name": "spring.cloud.gateway.x-forwarded.order",
      "description": "The order of the XForwardedHeadersFilter.",
      "type": "java.lang.Integer"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.port-append",
      "description": "If appending X-Forwarded-Port as a list is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.port-enabled",
      "description": "If X-Forwarded-Port is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.proto-append",
      "description": "If appending X-Forwarded-Proto as a list is enabled.",
      "type": "java.lang.Boolean"
    },
    {
      "sourceType": "org.springframework.cloud.gateway.filter.headers.XForwardedHeadersFilter",
      "defaultValue": true,
      "name": "spring.cloud.gateway.x-forwarded.proto-enabled",
      "description": "If X-Forwarded-Proto is enabled.",
      "type": "java.lang.Boolean"
    }

Summary

Spring cloud gateway provides XForwardedHeadersFilter, which is used to decide which X-Forwarded related headers to forward when routing forwarding, and append option to control whether to append or overwrite to the header.

doc