From 7a5f0998d211240ec06992d7a896cef7a926383d Mon Sep 17 00:00:00 2001 From: Stevenson Michel Date: Tue, 3 Mar 2026 17:08:38 -0500 Subject: [PATCH] [Devel] Added HTTP_X_FORWARDED_FOR in Devel for production (#16314) Added HTTP_X_FORWARDED_FOR in Devel for production --- awx/settings/production_defaults.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/awx/settings/production_defaults.py b/awx/settings/production_defaults.py index 190779ef28..02184abbda 100644 --- a/awx/settings/production_defaults.py +++ b/awx/settings/production_defaults.py @@ -19,6 +19,9 @@ SECRET_KEY = None # See https://docs.djangoproject.com/en/dev/ref/settings/#allowed-hosts ALLOWED_HOSTS = [] +# In production, trust the X-Forwarded-For header set by the reverse proxy +REMOTE_HOST_HEADERS = ['HTTP_X_FORWARDED_FOR'] + # Ansible base virtualenv paths and enablement # only used for deprecated fields and management commands for them BASE_VENV_PATH = os.path.realpath("/var/lib/awx/venv")