Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Reverse Proxy Header

1,704 sites Security covered Drupal 10–11
View on drupal.org

This module allows you to specify a custom HTTP header that contains the client's real IP address. This is useful when your reverse proxy or CDN uses a non-standard header for this information.

This module is the simplest way to use the specific HTTP header name to determine the client IP.

The module provides an equivalent of reverse_proxy_header setting (which is deprecated from Drupal 8.7.0).

The most common usage is:

  • real client IP is stored in some custom (non-default) header;
  • you cannot affect this on reverse proxy or server sides.

The module does not provide any UI. How to use it:
Step 1) Install the module via composer and enable it.
Step 2) Add the `reverse_proxy_header` configuration to your setting.php file:

/**
 * Sets the HTTP header name which stores the real client IP.
 *
 * @see https://www.drupal.org/project/reverse_proxy_header
 */
$settings["reverse_proxy_header"] = "HTTP_X_FORWARDED_FOR_CUSTOM_HEADER";

Here is an example for setting.php file to configure the module to use Cloudflare header only for some instances:

/**
 * Reverse Proxy Header module configuration.
 *
 * Determines the specific header name for some environments only.
 * And skips for others.
 *
 * @see https://www.drupal.org/project/reverse_proxy_header
 */
if (getenv("ENVIRONMENT_SPECIFIC_VARIABLE") === "value") {
  $settings["reverse_proxy_header"] = "HTTP_CF_CONNECTING_IP";
}

What about available alternatives?

  1. rename the header name (or copy its value) to the supported header HTTP_X_FORWARDED_FOR on proxy or server side;
  2. copy the value from the custom header to $_SERVER['HTTP_X_FORWARDED_FOR'] in your index.php before Drupal initialization;

πŸ‡ΊπŸ‡¦

This module is maintained by Ukrainian developers.
Please consider supporting Ukraine in a fight for their freedom and safety of Europe.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Jan 2025
Latest release
11 months ago
Releases (12 mo)
1 ▼ from 3
Maintenance
Slowing

Release Timeline

Releases

Version Type Core Release date
1.1.2 Stable 10–11 Sep 24, 2025
1.1.1 Stable 10–11 Jan 9, 2025
1.1.0 Stable 10–11 Jan 9, 2025
1.1.x-dev Dev 10–11 Jan 9, 2025