You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel中request()->ip()返回负载均衡IP而非客户端IP的问题排查与解决

Hey there! Let's figure out why request()->ip() is spitting out a private server IP instead of your users' real public IP—critical for your payment gateway to process requests correctly. Here's the breakdown of common causes and fixes:

Common Reasons This Happens

  • You're behind a reverse proxy/load balancer: Most production setups use tools like Nginx, Apache, or Cloudflare as a front-end proxy. When a user sends a request, it hits the proxy first, then gets forwarded to your Laravel app. By default, request()->ip() picks up the proxy's private IP instead of the original client's.
  • Proxy isn't passing the real IP header: Your proxy server might not be configured to send the client's real IP to your app via headers like X-Forwarded-For or X-Real-IP. Without these headers, your app has no way to know the actual client IP.
  • Laravel isn't trusting the proxy: Laravel blocks untrusted proxy headers by default (to prevent IP spoofing). If you don't tell it which proxies to trust, it'll ignore those forwarded IP headers entirely.

Step-by-Step Fixes

1. Configure Laravel to Trust Your Proxies

This is the safest and recommended approach. Laravel has built-in middleware to handle trusted proxies.

Open App\Http\Middleware\TrustProxies.php and update the $proxies array with your proxy server's IP range(s):

<?php

namespace App\Http\Middleware;

use Illuminate\Http\Request;
use Fideloper\Proxy\TrustProxies as Middleware;

class TrustProxies extends Middleware
{
    /**
     * The trusted proxies for this application.
     *
     * @var array<int, string>|string|null
     */
    protected $proxies = [
        '192.168.0.0/16', // Replace with your proxy's private IP range
        '10.0.0.0/8',
    ];

    /**
     * The headers that should be used to detect proxies.
     *
     * @var int
     */
    protected $headers = Request::HEADER_X_FORWARDED_ALL;
}

If you're using Cloudflare, you can find their official IP ranges and add them here instead. Never use '*' in production—this opens you up to IP spoofing attacks.

Once configured, request()->ip() will automatically pull the real client IP from the trusted proxy headers.

2. Update Your Proxy Server Configuration

Make sure your reverse proxy is actually sending the real client IP headers to your Laravel app.

For Nginx:

Add these lines to your site's configuration block:

location / {
    proxy_pass http://your-laravel-app-ip;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

Reload Nginx after making changes: sudo systemctl reload nginx

For Apache:

First, enable the mod_remoteip module:

sudo a2enmod remoteip

Then add these lines to your virtual host or .htaccess file:

RemoteIPHeader X-Forwarded-For
RemoteIPTrustedProxy 192.168.0.0/16 # Your proxy's IP range

Restart Apache: sudo systemctl restart apache2

3. Manual IP Retrieval (Last Resort)

If you can't configure trusted proxies right away, you can manually pull the IP from the forwarded headers—but this is risky for production since headers can be spoofed:

$realIp = request()->header('X-Forwarded-For') 
    ?? request()->header('X-Real-IP') 
    ?? request()->ip();

Only use this temporarily until you set up proper trusted proxy configuration.

4. Cloudflare-Specific Fix

If you're using Cloudflare, they send the real client IP in the CF-Connecting-IP header. Ensure your TrustProxies middleware includes Cloudflare's IP ranges, and Laravel will automatically use this header. Alternatively, you can explicitly get it with:

$realIp = request()->header('CF-Connecting-IP') ?? request()->ip();

Again, always pair this with trusted proxy configuration to avoid spoofing.

Final Note

Always prioritize the trusted proxy method—it's secure and aligns with Laravel's best practices. Using wildcard proxies or unvalidated headers can lead to security issues, especially for payment processing where IP accuracy matters.

内容的提问来源于stack exchange,提问作者Moeen Basra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:30:12