From 3855d78b2cf5c369f851e289297dd937bbaff3d6 Mon Sep 17 00:00:00 2001 From: Daniel Kesselberg Date: Sat, 9 Mar 2019 16:14:54 +0100 Subject: Make check for empty trusted proxies more strict Signed-off-by: Daniel Kesselberg --- settings/Controller/CheckSetupController.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'settings/Controller/CheckSetupController.php') diff --git a/settings/Controller/CheckSetupController.php b/settings/Controller/CheckSetupController.php index b23c48f4466..372a0a35e85 100644 --- a/settings/Controller/CheckSetupController.php +++ b/settings/Controller/CheckSetupController.php @@ -289,7 +289,7 @@ class CheckSetupController extends Controller { $trustedProxies = $this->config->getSystemValue('trusted_proxies', []); $remoteAddress = $this->request->getHeader('REMOTE_ADDR'); - if (empty($trustedProxies) && $this->request->getHeader('X-Forwarded-Host')) { + if ($trustedProxies === [] && $this->request->getHeader('X-Forwarded-Host') !== '') { return false; } -- cgit v1.2.3