#1745 - Make available config option for registering real IP within Composr when using CloudFlare instead of CloudFlare's IP
0 guests and 0 members have recently viewed this.
The top 3 point earners from 4th Jan 2026 to 11th Jan 2026.
| PDStig |
|
|
|---|---|---|
| Gabri |
|
|
| Adam Edington |
|
|
There are no events at this time
If there is no Cloudflare module on the server, then that means this IP is coming from an HTTP header. That means it is trivially forged by a hacker, with no negative consequences to them. If they managed to find the IP address of an admin, and session ID of an admin, they could steal that admin's login session. Finding the IP would be easy, just get them to view an image off their own server for example. Finding the session is much harder, but theoretically the admin could be tricked into it somehow.
So I'm not comfortable with the security degradation this represents.