Fix review comments on cookie banner API

Parse only the first IP from X-Forwarded-For to prevent
the full chain from bypassing anonymization. Add secondary
sort key for deterministic consent selection. Reject origins
with empty port suffix in the validator.

Signed-off-by: Émile Ré <emile@getprobo.com>
This commit is contained in:
Émile Ré
2026-04-14 15:44:48 +04:00
parent 30a86a91f1
commit 8ec434d67e
3 changed files with 10 additions and 2 deletions

View File

@@ -19,6 +19,7 @@ import (
"errors"
"net"
"net/http"
"strings"
"github.com/go-chi/chi/v5"
"go.gearno.de/kit/httpserver"
@@ -164,6 +165,13 @@ func (h *Handler) handlePostConsent(w http.ResponseWriter, r *http.Request) {
func clientIP(r *http.Request) string {
if xff := r.Header.Get("X-Forwarded-For"); xff != "" {
// X-Forwarded-For may contain a comma-separated chain; use only the
// leftmost (client) entry.
if i := strings.IndexByte(xff, ','); i != -1 {
xff = xff[:i]
}
xff = strings.TrimSpace(xff)
if ip, _, err := net.SplitHostPort(xff); err == nil {
return ip
}