You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Spring Boot 6+中替换/重写ForwardedHeaderTransformer?

Spring Boot 6+ 自定义可信代理的 ForwardedHeaderTransformer 实现

针对你需要仅处理预定义可信代理请求头的需求,以下分Servlet和WebFlux两种场景提供完整可行的实现方案,解决你之前自定义Transformer未被调用的问题:

Servlet 场景实现

1. 自定义 ForwardedHeaderTransformer

继承框架默认实现,添加可信代理判断逻辑:

import org.springframework.http.server.ServletServerHttpRequest;
import org.springframework.web.filter.ForwardedHeaderTransformer;
import java.util.Set;

public class TrustedProxyForwardedHeaderTransformer extends ForwardedHeaderTransformer {

    private final Set<String> trustedProxies;

    public TrustedProxyForwardedHeaderTransformer(Set<String> trustedProxies) {
        this.trustedProxies = trustedProxies;
    }

    @Override
    public ServletServerHttpRequest apply(ServletServerHttpRequest request) {
        // 获取请求来源的远程IP
        String remoteIp = request.getRemoteAddress().getAddress().getHostAddress();
        
        // 仅对可信代理发来的请求处理转发头,否则直接返回原请求
        if (trustedProxies.contains(remoteIp)) {
            return super.apply(request);
        }
        return request;
    }
}

2. 配置类注册并覆盖默认Bean

通过@Primary标记自定义Transformer,确保自动配置的ForwardedHeaderFilter使用该实现:

import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Primary;
import org.springframework.web.filter.ForwardedHeaderTransformer;
import java.util.Set;

@Configuration
public class ForwardedHeaderConfig {

    // 读取配置文件中的可信代理列表
    @Bean
    @ConfigurationProperties(prefix = "app")
    public TrustedProxyProperties trustedProxyProperties() {
        return new TrustedProxyProperties();
    }

    // 注册自定义Transformer并设置为优先使用
    @Bean
    @Primary
    public ForwardedHeaderTransformer trustedProxyForwardedHeaderTransformer(TrustedProxyProperties properties) {
        return new TrustedProxyForwardedHeaderTransformer(properties.getTrustedProxies());
    }

    // 配置属性映射类
    public static class TrustedProxyProperties {
        private Set<String> trustedProxies;

        public Set<String> getTrustedProxies() {
            return trustedProxies;
        }

        public void setTrustedProxies(Set<String> trustedProxies) {
            this.trustedProxies = trustedProxies;
        }
    }
}

3. 配置文件(application.yaml)

启用框架级转发头处理,并配置可信代理列表:

server:
  forward-headers-strategy: framework
app:
  trusted-proxies:
    - 192.168.1.100
    - 10.0.0.5

WebFlux 场景实现

WebFlux 使用HttpHandler处理请求,需通过自定义WebHttpHandlerBuilder替换默认Transformer:

1. 自定义 ForwardedHeaderTransformer

import org.springframework.http.server.reactive.ServerHttpRequest;
import org.springframework.web.server.adapter.ForwardedHeaderTransformer;
import java.util.Set;

public class TrustedProxyForwardedHeaderTransformer extends ForwardedHeaderTransformer {

    private final Set<String> trustedProxies;

    public TrustedProxyForwardedHeaderTransformer(Set<String> trustedProxies) {
        this.trustedProxies = trustedProxies;
    }

    @Override
    public ServerHttpRequest apply(ServerHttpRequest request) {
        String remoteIp = request.getRemoteAddress().getAddress().getHostAddress();
        
        if (trustedProxies.contains(remoteIp)) {
            return super.apply(request);
        }
        return request;
    }
}

2. 配置类自定义 HttpHandler

import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.web.server.adapter.WebHttpHandlerBuilder;
import java.util.Set;

@Configuration
public class ForwardedHeaderConfig {

    @Bean
    @ConfigurationProperties(prefix = "app")
    public TrustedProxyProperties trustedProxyProperties() {
        return new TrustedProxyProperties();
    }

    // 通过Customizer替换默认的ForwardedHeaderTransformer
    @Bean
    public WebHttpHandlerBuilder.Customizer httpHandlerCustomizer(TrustedProxyProperties properties) {
        return builder -> {
            TrustedProxyForwardedHeaderTransformer transformer = 
                new TrustedProxyForwardedHeaderTransformer(properties.getTrustedProxies());
            builder.transformers(transformer);
        };
    }

    public static class TrustedProxyProperties {
        private Set<String> trustedProxies;

        public Set<String> getTrustedProxies() {
            return trustedProxies;
        }

        public void setTrustedProxies(Set<String> trustedProxies) {
            this.trustedProxies = trustedProxies;
        }
    }
}

3. 配置文件(application.yaml)

同Servlet场景配置:

server:
  forward-headers-strategy: framework
app:
  trusted-proxies:
    - 192.168.1.100
    - 10.0.0.5

关键说明

你之前的方案无效的核心原因:

  • Servlet场景:未通过@Primary覆盖默认的ForwardedHeaderTransformer,导致自动配置的ForwardedHeaderFilter仍使用框架默认实现
  • WebFlux场景:未在WebHttpHandlerBuilder中替换Transformer,自定义逻辑未被接入请求链路

如果需要支持CIDR格式的IP范围(如192.168.1.0/24),可引入Apache Commons Net库的SubnetUtils类实现IP范围匹配。

内容的提问来源于stack exchange,提问作者BUKTOP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 06:34:54