Compare commits

..

3 Commits
v0.6.1 ... main

Author SHA1 Message Date
1aedddc66e feat: update package name 2024-06-12 22:02:42 +00:00
dongwei
445f9dd037 add docker ip 2019-02-28 14:20:42 +08:00
George Xie
436a084581 非生产环境的 server 不对检查客户端 ip 白名单 2018-06-26 10:50:49 +08:00
4 changed files with 93 additions and 1251 deletions

View File

@ -1,5 +1,5 @@
{
"name": "arch/php-internal-api-client",
"name": "paidian/php-internal-api-client",
"type": "library",
"require": {
"guzzlehttp/guzzle": "^6.3",

1194
composer.lock generated

File diff suppressed because it is too large Load Diff

View File

@ -15,6 +15,27 @@ class InternalApi
app()->configure('internal_api');
}
private function isClientIPPermitted($ip)
{
if (!app()->environment('production', 'staging')) {
return true;
}
if (Str::startsWith($ip, [
'127.0.0.1',
//局域网
'192.168.',
//vpc
'10.0.',
//pod network
'172.20.',
//北京办公区
'172.16.'
])) {
return true;
}
return false;
}
/**
* Handle an incoming request.
*
@ -25,11 +46,8 @@ class InternalApi
public function handle($request, Closure $next)
{
$ip = $request->getClientIp();
if (!Str::startsWith($ip, [
'127.0.0.', '192.168.', '10.0.'
])) {
return new JsonResponse('', 404);
if (!$this->isClientIPPermitted($ip)) {
return new JsonResponse("$ip is forbidden", 403);
}
$params = $request->all();

View File

@ -2,8 +2,26 @@
namespace PdInternalApi;
use Illuminate\Http\Request;
class ServiceProvider extends \Illuminate\Support\ServiceProvider
{
public function boot(){
Request::setTrustedProxies([
//pod network
'172.20.0.0/16',
//vpc
'10.0.0.0/16',
//local
'127.0.0.1',
//北京办公区
'172.16.0.0/16',
//aliyun slb
'100.116.0.0/16',
], Request::HEADER_X_FORWARDED_ALL);
}
/**
* Register any application services.
*