note 7799 deleted from function.getenv by cmb
| From: | cmb@php.net | Date: | Tue, 19 May 2015 12:00:45 +0000 |
| Subject: | note 7799 deleted from function.getenv by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-202601@lists.php.net to get a copy of this message | ||
Note Submitter: john-php at pc dot xs4all dot nl
----
Note that the X-Forwarded for header might contain multiple addresses, comma separated, if the
request was forwarded through multiple proxies.
Finally, note that any user can add an X-Forwarded-For header themselves. The header is only good
for traceback information, never for authentication. If you use it for traceback, just log the
entire X-Forwarded-For header, along with the REMOTE_ADDR.