|
|
|
|
@ -12,7 +12,7 @@ class TrustProxies extends Middleware
|
|
|
|
|
*
|
|
|
|
|
* @var array<int, string>|string|null
|
|
|
|
|
*/
|
|
|
|
|
protected $proxies = '*';
|
|
|
|
|
protected $proxies;
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* The headers that should be used to detect proxies.
|
|
|
|
|
@ -25,4 +25,12 @@ class TrustProxies extends Middleware
|
|
|
|
|
Request::HEADER_X_FORWARDED_PORT |
|
|
|
|
|
Request::HEADER_X_FORWARDED_PROTO |
|
|
|
|
|
Request::HEADER_X_FORWARDED_AWS_ELB;
|
|
|
|
|
|
|
|
|
|
public function handle($request, \Closure $next)
|
|
|
|
|
{
|
|
|
|
|
// 本地 APP_URL 为 http 时不信任 X-Forwarded-Proto,避免首页/登录链接被拼成 https
|
|
|
|
|
$this->proxies = str_starts_with((string) config('app.url'), 'https://') ? '*' : [];
|
|
|
|
|
|
|
|
|
|
return parent::handle($request, $next);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|