Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

`client-ip` is not an IP address when `x-forwarded-for` holds a list or a port

Aperta Adatta ai principianti
#8,532 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@Dev-next-gen ci sta già lavorando.

Dal 27/9/2026.

  • #8533 di @Dev-next-gen — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
node.js, typescript
Ambito
backend, cli

Direzione di ricerca

Inizia in src/lib/functions/server.ts da createHandler, quindi confronta la gestione delle requests circostante con src/utils/proxy.ts. Esegui la riproduzione dell'issue con functions:serve usando entrambi gli esempi di x-forwarded-for. Il lavoro è completato quando client-ip e x-nf-client-connection-ip contengono ciascuno un IP valido per quegli input, mentre netlify dev rimane invariato.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Describe the bug

Under netlify functions:serve, the client-ip and x-nf-client-connection-ip headers that
reach a serverless function are not always an IP address. They can be the whole
x-forwarded-for list, or a port number.

createHandler builds the value like this (src/lib/functions/server.ts):

let remoteAddress = request.header('x-forwarded-for') || request.connection.remoteAddress || ''
remoteAddress = remoteAddress.split(remoteAddress.includes('.') ? ':' : ',').pop()?.trim() ?? ''

The separator is chosen from whether the string contains a dot, so a comma-separated IPv4 list
is never split on the comma.

Steps to reproduce
mkdir -p netlify/functions
cat > netlify/functions/whoami.js <<'EOF'
exports.handler = async (event) => ({
  statusCode: 200,
  body: JSON.stringify({ clientIp: event.headers['client-ip'] }),
})
EOF

netlify functions:serve --port 9999 &
curl -s -H 'x-forwarded-for: 1.2.3.4, 5.6.7.8' localhost:9999/.netlify/functions/whoami
curl -s -H 'x-forwarded-for: 1.2.3.4:5678'     localhost:9999/.netlify/functions/whoami
Expected behavior

One IP address, i.e. net.isIP(clientIp) !== 0.

Actual behavior
{"clientIp":"1.2.3.4, 5.6.7.8"}
{"clientIp":"5678"}

net.isIP() returns 0 for both. A function that parses client-ip, compares it, or
passes it to a geo/rate-limit library gets a value that cannot be an address, and this
only shows up locally — in production Netlify sends a single address.

Note that netlify dev is unaffected: the dev proxy overwrites x-forwarded-for with
req.connection.remoteAddress before the functions server sees it
(src/utils/proxy.ts), so a single address always arrives. functions:serve runs the
functions server without that proxy, so the client's own header is used verbatim.

Environment
  • netlify-cli 27.10.0 (main at 904515c)
  • Node 22.23.3
Lingua principale
TypeScript
Stelle
1.9k
Fork
478
Merge medio
1g 18h
PR unite (30g)
37

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di netlify/cli

Tutte le issue di netlify/cli

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.