Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Usage Milestone: Time Field for Drupal 8+ Module time_field crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Trusted Reverse Proxy

606 sites Security covered Drupal 10–11
View on drupal.org

This module helps Drupal sites running behind trusted reverse proxies correctly identify the client's IP address by inspecting headers like X-Forwarded-For. It also adjusts system status reports to acknowledge this setup, preventing unnecessary errors. Use this module only if you fully trust your upstream reverse proxies and understand the security implications.

A simple module designed to run on sites that are known to operate in environment(s) behind known trusted reverse proxies. This module presently performs a number of specific tasks:

  • Inspecting x-forwarded-for headers to identify reverse proxies and trust the left-most IP found as the client IP. (For instance, you may be behind no or only one reverse proxy during local development but behind CloudFlare and a TLS-terminating reverse proxy and then Varnish in production.
  • Demoting the status report/requirements error for a missing trusted host pattern setting to a "checked" finding. This is a proposed change in Core: #3166866: Don't raise requirements error when no trusted_host_patterns and behind trusted reverse proxy

Why a contrib module? This is complex enough a set of overrides that it is not easily accomplished in one or two configuration changes, and hopefully this project provides a collection point for best practices on keeping Drupal a best-in-class cloud native product by adopting sensible defaults in the cloud.

Scary-sounding warning

This module is all about trusting your upstream reverse proxies. If you don't trust them, don't use this module.

Furthermore, if you don't fully understand why you would do such a thing, don't use this module.

Things to consider:

  • Does your first-hop reverse proxy rewrite `x-forwarded-for` instead of passing through any headers received from the client request?
  • Are your remaining hops on a private network, or otherwise restrict communication from only trusted reverse proxies?
  • Do you understand HTTP mechanics sufficiently to understand the implications of implementing this module?

Basically, if clients are able to spoof the x-forwarded-for header, things like IP blacklisting/whitelisting, fail-2-ban by IP, or other such features on your site could be circumvented. Know your upstream.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
3
Tracked since
Aug 2025
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 3
Maintenance
Dormant

Release Timeline

Releases

Version Type Core Release date
1.3.1 Stable 10–11 Aug 4, 2025
1.3.0 Stable 9–10 Aug 4, 2025
1.3.x-dev Dev 10–11 Aug 4, 2025